Courseiva

CCNA Design business continuity solutions Questions

75 of 152 questions · Page 1/3 · Design business continuity solutions · Answers revealed

1
MCQmedium

A company runs a legacy on-premises application that relies on a SQL Server database. They want to use Azure as a disaster recovery site with a recovery point objective of less than 15 minutes. They need to be able to fail back to the on-premises environment after a disaster. Which Azure service should they use?

A.Azure Site Recovery
B.Azure Backup
C.Azure SQL Database
D.Azure Traffic Manager
AnswerA

Azure Site Recovery is the correct DR solution because it continuously replicates on-premises VMs and physical servers to Azure using asynchronous replication, typically achieving a recovery point objective (RPO) of 30 seconds or less. It provides orchestrated failover to Azure and failback to on-premises, enabling the legacy application to run on Azure during a disaster while maintaining application consistency through multi-VM consistency groups.

Why this answer

Azure Site Recovery (ASR) orchestrates replication, failover, and failback of on-premises SQL Server workloads to Azure, supporting a Recovery Point Objective (RPO) of less than 15 minutes through continuous replication. It enables failback to the original on-premises environment after a disaster, which is a critical requirement for this scenario.

Exam trap

The trap here is that candidates often confuse Azure Backup (which is for archival backups) with Azure Site Recovery (which is for replication and failover), leading them to select Azure Backup despite its inability to meet the sub-15-minute RPO or support failback.

How to eliminate wrong answers

Option B (Azure Backup) is wrong because it provides point-in-time backups with a typical RPO of hours or daily, not sub-15-minute continuous replication, and it does not support orchestrated failback to on-premises. Option C (Azure SQL Database) is wrong because it is a PaaS database service that cannot replicate an on-premises SQL Server instance for failback; it would require migrating the database schema and data, not providing disaster recovery replication. Option D (Azure Traffic Manager) is wrong because it is a DNS-based traffic load balancer that routes user traffic, not a replication or disaster recovery service for SQL Server databases.

2
MCQhard

A company runs a critical database on Azure SQL Database in the West US region. They need to implement disaster recovery to East US with an RPO of 1 minute and RTO of 1 hour. They also want to use the secondary database for read-only workloads during normal operations. The solution must be fully managed. Which Azure SQL Database feature should they enable?

A.Active geo-replication with failover group
B.Auto-failover group with read-scale
C.Geo-restore
D.Zone-redundant configuration
AnswerB

Auto-failover groups manage failover for one or more databases, support read-only access to the secondary, and meet the RPO/RTO requirements.

Why this answer

Auto-failover groups with read-scale (Option B) provide a fully managed disaster recovery solution with an RPO of 1 minute and RTO of 1 hour. They allow the secondary database in East US to be used for read-only workloads during normal operations via the read-scale listener endpoint. This meets all requirements: fully managed, low RPO/RTO, and read-only access to the secondary.

Option A (Active geo-replication with failover group) does not support automatic failover and does not provide a read-scale endpoint for the secondary, so it does not meet the RTO requirement or the read-only workload requirement.

Exam trap

The trap here is confusing Active geo-replication (manual failover, no read-scale) with Auto-failover groups (automatic failover, read-scale), leading candidates to pick Option A even though it lacks the read-scale capability and automatic RTO guarantee.

How to eliminate wrong answers

Option A is wrong because Active geo-replication alone does not include a failover group; without the failover group, you cannot achieve the 1-hour RTO (manual failover takes longer) and you lose the automatic orchestration of read-scale endpoints. Option C is wrong because Geo-restore is a point-in-time recovery method with an RPO of 1 hour and RTO of 12-24 hours, far exceeding the required 1-minute RPO and 1-hour RTO, and it does not support read-only workloads on a secondary. Option D is wrong because Zone-redundant configuration provides high availability within a single region, not disaster recovery across regions, and does not offer a secondary for read-only workloads.

3
MCQeasy

A company runs an Azure SQL Database in a single region. They need to ensure that the database can be restored to any point in time within the last 90 minutes with a granularity of 1 minute. Which feature should they enable?

A.Active geo-replication
B.Auto-failover groups
C.Point-in-time restore
D.Long-term backup retention
AnswerC

Point-in-time restore leverages Azure SQL Database's automatic backups—full, differential, and transaction log backups taken every 5–10 minutes—to recreate a database at any second within the configured retention period (default 7 days, up to 35 days). You specify a target timestamp, and Azure calculates the precise log sequence number, restores the nearest full backup, and replays transaction logs to that point. This exactly matches the 1-minute granularity requested, making it the correct solution for recovering a recent data corruption or accidental deletion.

Why this answer

Point-in-time restore (PITR) for Azure SQL Database automatically creates backups every 5-10 minutes and retains them for the default retention period of 7 days (configurable up to 35 days). This allows restoring the database to any second within the retention window, meeting the requirement of 1-minute granularity for the last 90 minutes. The feature is built-in and does not require any additional configuration beyond setting the desired retention period.

Exam trap

The trap here is that candidates often confuse point-in-time restore with disaster recovery features like geo-replication or failover groups, but the question specifically asks for restoring to a point in time within 90 minutes with 1-minute granularity, which is exclusively provided by PITR.

How to eliminate wrong answers

Option A is wrong because Active geo-replication is designed for continuous data replication to a secondary region for disaster recovery, not for point-in-time restores within a single region. Option B is wrong because Auto-failover groups manage automatic failover of multiple databases across regions, but they do not provide point-in-time restore capability. Option D is wrong because Long-term backup retention (LTR) extends backup retention beyond 35 days (up to 10 years) using weekly, monthly, or yearly backups, but it does not offer the 1-minute granularity required for the last 90 minutes; LTR backups are taken at coarser intervals.

4
Multi-Selecthard

A solution stores critical VM backups in Azure. The company wants protection against accidental or malicious deletion of backups. Which two controls should be included?

Select 2 answers
A.Disabling backup alerts
B.Storing all backups on the original VM disk
C.Soft delete for Azure Backup
D.Multi-user authorization or resource locks where applicable
AnswersC, D

Soft delete for Azure Backup adds a mandatory 14-day (by default) retention window for any deleted backup data, during which the recovery point can be recovered even if a user, script, or attacker deletes it. This protects against accidental deletes and malicious actions because the data is not immediately purged; an administrator can restore it by selecting 'Undelete' while the vault has soft delete enabled. It also raises the bar for ransomware operators by preventing them from erasing backup history in one operation, making it a core data-recovery safeguard for critical VM backups.

Why this answer

Soft delete for Azure Backup (Option C) is correct because it retains backup data for an additional 14 days after deletion, allowing recovery from accidental or malicious deletion. This feature is enabled by default for Recovery Services vaults and protects backup data even if the backup itself is deleted, providing a critical safety net against data loss.

Exam trap

The trap here is that candidates may overlook the need for both a data-level protection (soft delete) and a resource-level protection (resource locks), assuming one control is sufficient, or they may mistakenly think disabling alerts or storing backups on the same disk provides any deletion protection.

5
Multi-Selectmedium

A company uses Azure Site Recovery to replicate VMs from the primary region to the secondary region. During a disaster, they want to ensure that the failover process is automated and includes runbooks to perform post-failover actions. Which TWO components are required? (Choose two.)

Select 2 answers
A.Azure Automation runbooks
B.Azure Site Recovery Recovery Plans
C.Azure Monitor alerts
D.Azure Logic Apps
E.Azure Backup
AnswersA, B

Azure Automation runbooks are PowerShell or Python scripts that ASR executes as steps inside a Recovery Plan, enabling custom post-failover actions such as updating DNS records, changing IP addresses, or reconfiguring application dependencies. They are correct because they provide the scripted logic that makes failover automation truly workload-aware, and they run either on an Azure Hybrid Worker or in Azure after the VMs start.

Why this answer

Azure Automation runbooks are required because they contain the PowerShell or Python scripts that execute post-failover actions, such as updating DNS records, reconfiguring network settings, or starting dependent services. Azure Site Recovery Recovery Plans are required because they orchestrate the failover sequence, including grouping VMs into ordered groups and invoking runbooks at specific steps. Together, they enable automated, scripted post-failover tasks within a structured failover workflow.

Exam trap

The trap here is that candidates often confuse Azure Logic Apps with Azure Automation runbooks, but only runbooks are directly supported within Azure Site Recovery Recovery Plans for post-failover automation.

6
MCQmedium

A company runs a three-tier application on Azure VMs in the West US region. They want to enable disaster recovery to East US using Azure Site Recovery. The application requires that the web tier starts first, then the application tier, and finally the database tier after a consistency check. They also need to be able to perform non-disruptive DR drills. Which Azure Site Recovery capabilities should they use together?

A.Recovery Plan with pre/post actions and Test Failover
B.Network mapping and IP customization
C.Replication policy with crash-consistent snapshots
D.Azure Automation runbooks and Azure Monitor alerts
AnswerA

An Azure Site Recovery Recovery Plan is the only construct that explicitly determines failover behavior across multiple VMs: you group VMs into ordered groups, and attach pre/post actions via Azure Automation runbooks or custom scripts to stop or start tiers in dependency order (for example, database before middleware before web). The Test Failover feature then executes that exact plan against an isolated Azure Virtual Network, validating scripts, IP assignments, and application startup without affecting the production endpoint. This combination directly addresses both the startup sequencing requirement and the need for periodic non-disruptive drills.

Why this answer

A Recovery Plan in Azure Site Recovery allows you to define the startup order of tiers (web, app, database) using pre-actions and post-actions, which can invoke Azure Automation runbooks or scripts to perform the consistency check. Test Failover enables non-disruptive DR drills by creating an isolated copy of the replicated VMs in East US without impacting the production environment. Together, these capabilities meet both the ordered startup and drill requirements.

Exam trap

The trap here is that candidates may confuse general Azure automation or networking features (like runbooks or network mapping) with the specific ASR capabilities required for ordered startup and drills, overlooking that Recovery Plan and Test Failover are the exact ASR features designed for these purposes.

How to eliminate wrong answers

Option B is wrong because network mapping and IP customization handle network connectivity and IP address assignment during failover, but they do not control the startup order of tiers or enable non-disruptive drills. Option C is wrong because a replication policy with crash-consistent snapshots provides a point-in-time copy of VMs, but it does not orchestrate the sequence of tier startup or support test failovers. Option D is wrong because Azure Automation runbooks and Azure Monitor alerts can automate tasks and monitor health, but they are not native ASR capabilities for defining recovery plan steps or performing DR drills; runbooks can be used within recovery plans, but the question asks for ASR capabilities, and alerts alone do not enable drills.

7
Multi-Selecthard

Which THREE of the following are best practices for designing a business continuity solution using Azure Site Recovery? (Select THREE.)

Select 3 answers
A.Configure automatic failover for all VMs without manual intervention
B.Perform test failovers regularly to validate the recovery plan
C.Use recovery plans to orchestrate failover of multi-tier applications
D.Use a single target region for all VMs to simplify management
E.Enable replication for all VMs that are critical to the application
AnswersB, C, E

Perform test failovers regularly to validate the recovery plan and ensure your documented RTOs and RPOs remain achievable. Test failovers in Azure Site Recovery spin up replicated copies in an isolated Azure virtual network, so you can verify application startup, networking, and dependencies without impacting production. Regular testing surfaces broken scripts, outdated credentials, or misconfigured DNS that would otherwise only appear during a real disaster.

Why this answer

Azure Site Recovery (ASR) recommends performing test failovers regularly to validate that the recovery plan works as expected without impacting production workloads. Test failovers use isolated networks to verify replication health, application consistency, and RTO/RPO targets, ensuring the actual failover process is reliable.

Exam trap

The trap here is that candidates may confuse 'automatic failover' with 'automated recovery plans' and select Option A, not realizing that ASR deliberately avoids automatic failover to prevent accidental disruption, and instead relies on manual or scripted triggers.

8
MCQmedium

A company runs a mission-critical multi-tier application on Azure VMs in West US. The application consists of database VMs, application VMs, and web VMs. During a disaster, the VMs must be recovered in a specific order: database tier first, then application tier, then web tier. The recovery point objective (RPO) is 5 minutes and recovery time objective (RTO) is 15 minutes. The company wants to periodically test the recovery process without impacting production. After failover to East US, the VMs must retain their private IP addresses to avoid DNS propagation delays. Which combination of Azure Site Recovery features should they configure?

A.A recovery plan, planned failover, and network mapping
B.A recovery plan, test failover, and network mapping
C.A recovery plan, test failover, and static IP address assignment
D.A recovery plan, planned failover, and static IP address assignment
AnswerC

Recovery Plan defines the order of VM group failover and can incorporate Automation runbooks for post-failover customizations, such as updating DNS records. Test failover enables you to validate the entire recovery flow in an isolated test network safely, without any impact to the production source VMs. By explicitly assigning a static IP address to each VM in the target subnet, you guarantee the same IP is used after failover, which is crucial for applications with hard-coded IP dependencies. This combination fully meets the requirement: orchestrated, tested, and IP-preserving failover.

Why this answer

A recovery plan enforces the required startup order (database → application → web), test failover allows non-disruptive validation of the recovery process, and static IP address assignment ensures VMs retain their private IP addresses after failover to East US, avoiding DNS propagation delays. This combination meets the RPO of 5 minutes and RTO of 15 minutes while satisfying the requirement for periodic testing without impacting production.

Exam trap

The trap here is that candidates confuse network mapping (which only maps source to target networks) with static IP address assignment (which preserves the exact private IP), leading them to choose Option B instead of C.

How to eliminate wrong answers

Option A is wrong because planned failover is used for zero-data-loss migrations or planned downtime scenarios, not for disaster recovery testing, and it does not support non-disruptive validation of the recovery process. Option B is wrong because network mapping only maps source and target networks for IP address assignment but does not guarantee that VMs retain their exact private IP addresses after failover; static IP assignment is required for that. Option D is wrong because planned failover is not suitable for periodic testing of disaster recovery, as it assumes a controlled shutdown and can impact production if used incorrectly.

9
MCQeasy

Your organization runs a web application on Azure App Service (Standard tier) in the West US region. The application uses Azure Blob Storage for static content and Azure SQL Database (Standard tier) for dynamic data. The compliance requirements specify a Recovery Point Objective (RPO) of 1 hour and a Recovery Time Objective (RTO) of 4 hours. You need to design a disaster recovery solution that meets these requirements with minimal cost. Which option should you recommend?

A.Deploy App Service in two regions with Azure Traffic Manager. Use Azure Site Recovery to replicate the App Service and SQL Database. Enable geo-redundant storage for Blob Storage.
B.Deploy App Service in two regions with Azure Front Door. Use active geo-replication for Azure SQL Database. Enable read-access geo-redundant storage (RA-GRS) for Blob Storage.
C.Use Azure Traffic Manager to distribute traffic. Manually copy Blob Storage to a secondary region. Use Azure SQL Database export to bacpac and import in secondary region.
D.Configure App Service backup to a geo-redundant storage account. Use geo-redundant storage (GRS) for Blob Storage. Enable geo-restore for Azure SQL Database.
AnswerD

Configuring App Service backup to a geo-redundant storage account ensures that application content, including code and configuration, is automatically replicated to the paired region, which is essential because App Service itself has no built-in geo-replication. GRS for Blob Storage automatically replicates blobs to the secondary region, providing a synchronous (or async, depending on service tier) copy that can be used for failover without manual intervention. Enabling geo-restore for Azure SQL Database uses the geo-redundant backups that Azure maintains automatically, offering an RPO of up to 1 hour, which aligns exactly with the stated requirement. Together these components give a fully automated, PaaS-native disaster recovery approach with no need for Site Recovery, Front Door, or manual data copies.

Why this answer

Meets the RPO of 1 hour and RTO of 4 hours at minimal cost by using App Service backup to geo-redundant storage (which can be restored within the RTO), geo-redundant storage (GRS) for Blob Storage (providing automatic replication to a paired region), and geo-restore for Azure SQL Database (which restores from geo-replicated backups with an RPO of 1 hour and RTO typically under 4 hours). This approach avoids the cost and complexity of running active secondary instances.

Exam trap

The trap here is that candidates often assume active-active or active-passive multi-region deployments (like Traffic Manager or Front Door) are required for DR, but Azure's built-in geo-restore and geo-redundant storage features can meet moderate RPO/RTO targets at a fraction of the cost without running duplicate resources.

How to eliminate wrong answers

Option A is wrong because Azure Site Recovery does not support replicating Azure App Service or Azure SQL Database (it is for IaaS VMs and physical servers); also, using Traffic Manager with two active App Service instances incurs higher cost than needed. Option B is wrong because active geo-replication for Azure SQL Database requires a Premium or Business Critical tier, not the Standard tier, and Azure Front Door adds unnecessary cost and complexity for a passive DR scenario. Option C is wrong because manually copying Blob Storage and using bacpac export/import cannot achieve an RPO of 1 hour (bacpac exports are point-in-time and can take hours) and the manual process exceeds the RTO of 4 hours.

10
MCQhard

A company runs a critical application on Azure SQL Database in the West US region. They need a disaster recovery solution with an RPO of 5 seconds and an RTO of 1 hour. They also need to be able to perform patching and maintenance on the primary without downtime. Which configuration should they implement?

A.Active geo-replication with auto-failover group
B.Azure SQL Database backup to geo-redundant storage
C.Azure SQL Database with zone-redundant configuration
D.Azure SQL Database with failover group using manual failover
AnswerA

Active geo-replication with auto-failover group continuously streams transaction log changes from the primary database to a secondary replica in a paired region, providing a recovery point objective (RPO) of up to 5 seconds and a recovery time objective (RTO) of about 1 hour. The auto-failover group adds an orchestration layer that monitors health and triggers failover automatically, and also enables a planned failover that fully synchronizes before switching so no data is lost during maintenance. For a critical application, this combination meets stringent RPO/RTO requirements while keeping downtime minimal.

Why this answer

Active geo-replication with auto-failover group meets the RPO of 5 seconds (typically under 5 seconds for active geo-replication) and RTO of 1 hour (auto-failover groups can fail over in minutes). It also supports patching and maintenance on the primary without downtime by failing over to a secondary replica during planned maintenance, leveraging the continuous data synchronization between primary and secondary databases in different Azure regions.

Exam trap

The trap here is that candidates confuse zone-redundant configuration (which only protects within a region) with geo-redundant disaster recovery, or they assume manual failover can meet strict RTOs without considering the human delay factor.

How to eliminate wrong answers

Option B is wrong because Azure SQL Database backup to geo-redundant storage (RA-GRS) provides an RPO of up to 12 hours and RTO of 12-24 hours, far exceeding the required 5-second RPO and 1-hour RTO, and does not support zero-downtime patching. Option C is wrong because zone-redundant configuration protects against zonal failures within a single region, not against regional disasters, and cannot meet the RPO/RTO for cross-region DR. Option D is wrong because a failover group using manual failover requires human intervention to trigger failover, which cannot achieve the 1-hour RTO reliably and does not support automated zero-downtime patching without manual steps.

11
MCQmedium

A company runs a web application on Azure App Service with a Standard tier plan. The application uses an Azure SQL Database (DTU-based) for storage. The business requires that the application remain available in the event of a single Azure region outage. Which solution meets the requirement with the least administrative effort?

A.Use an App Service Environment (ASE) in a single region with App Service plans in multiple availability zones
B.Use Azure Front Door to route traffic to a secondary App Service in the same region
C.Configure Azure Backup for the App Service and SQL Database
D.Deploy an additional App Service in a secondary region and use Azure SQL Database active geo-replication
AnswerD

Deploying a second App Service in a secondary Azure region and configuring active geo-replication for Azure SQL Database is the standard, simplest disaster recovery pattern. Active geo-replication continuously replicates up to four readable secondary databases to the paired or chosen region, enabling a failover group that can automatically or manually promote the secondary to primary with minimal downtime. The additional App Service in that secondary region can then serve traffic once DNS records are switched (for example, via Azure Traffic Manager or Azure Front Door), meeting a cross-region disaster recovery requirement without needing a full standby environment.

Why this answer

Deploying an additional App Service in a secondary region and using Azure SQL Database active geo-replication ensures that both the compute and data tiers can fail over to a different Azure region during a regional outage. Active geo-replication creates readable secondary replicas of the SQL Database in the paired region, and with App Service, you can use Azure Front Door or Traffic Manager to route traffic to the secondary instance. This solution meets the availability requirement with minimal administrative overhead, as geo-replication is managed by Azure and does not require complex manual synchronization.

Exam trap

The trap here is that candidates often confuse availability zones (which protect against datacenter failures within a region) with region pairs (which protect against full regional outages), leading them to choose Option A or B incorrectly.

How to eliminate wrong answers

Option A is wrong because an App Service Environment (ASE) in a single region with App Service plans in multiple availability zones protects only against zonal failures within that region, not against a full regional outage. Option B is wrong because using Azure Front Door to route traffic to a secondary App Service in the same region does not provide resilience against a regional outage; both instances would be affected simultaneously. Option C is wrong because Azure Backup is designed for data protection and recovery from accidental deletion or corruption, not for maintaining continuous availability during a regional outage; it involves downtime during restore operations.

12
MCQhard

Contoso Ltd. is a global e-commerce company running its online store on Azure. The application consists of: - Frontend: Azure App Service (Windows) in West US. - Backend: Azure Kubernetes Service (AKS) cluster in West US. - Database: Azure SQL Database (General Purpose, S2) in West US. - Cache: Azure Cache for Redis (Standard C1) in West US. - Storage: Azure Blob Storage (LRS) for product images. Business continuity requirements: - RPO: 5 minutes for the database. - RTO: 1 hour for the entire application. - The solution must survive a complete West US region outage. - Budget is limited; minimize additional costs. What should you recommend as the primary DR strategy?

A.Deploy a secondary region (East US) with a passive AKS cluster (minimal node count), a standby App Service plan (same tier), and a secondary Azure SQL Database in an auto-failover group. Use Azure Traffic Manager for frontend and configure Azure Cache for Redis with geo-replication. For Blob Storage, enable geo-redundant storage (GRS).
B.Use Azure Backup for the database with 5-minute log backup frequency. For the app, use Azure App Service backup with frequency to a secondary region. For AKS, back up persistent volumes using Azure Backup. Restore everything in a secondary region during disaster.
C.Deploy the entire application across two Azure Availability Zones within West US. Use zone-redundant storage for blobs, zone-redundant App Service plan, and zone-redundant AKS. For SQL Database, use a zone-redundant configuration. For Redis, use Enterprise tier with zone redundancy.
D.Use Azure Site Recovery to replicate all VMs (including AKS nodes) to a secondary region. For the database, use Azure SQL Database active geo-replication. For Azure Cache for Redis, replicate data via geo-replication. Use Azure Traffic Manager for frontend traffic routing.
AnswerA

A passive secondary region with auto-failover groups meets the 5-minute database RPO and 1-hour RTO, while Traffic Manager, Redis geo-replication and GRS cover the remaining tiers. Minimal AKS nodes and a standby plan keep costs low, satisfying the limited-budget constraint.

Why this answer

It meets the RPO of 5 minutes for the database using an auto-failover group with a secondary Azure SQL Database in East US, which provides continuous data synchronization with minimal data loss. The passive AKS cluster (minimal node count) and standby App Service plan minimize costs while ensuring RTO of 1 hour by allowing rapid scaling during failover. Azure Traffic Manager routes frontend traffic to the secondary region, and geo-replication for Redis Cache and GRS for Blob Storage provide data durability across regions, satisfying the requirement to survive a complete West US region outage.

Exam trap

The trap here is that candidates often choose zone-redundant options (Option C) thinking they provide regional resilience, but they only protect against zone failures within a region, not a complete region outage, which is explicitly required in the question.

How to eliminate wrong answers

Option B is wrong because Azure Backup with 5-minute log backup frequency can achieve an RPO of 5 minutes, but restoring the entire application in a secondary region during a disaster would likely exceed the 1-hour RTO due to the time required to restore App Service backups, AKS persistent volumes, and database backups, and it does not provide automated failover or pre-provisioned infrastructure. Option C is wrong because deploying across Availability Zones within West US cannot survive a complete region outage, as all zones are in the same region; this violates the requirement to survive a full West US region outage. Option D is wrong because Azure Site Recovery replicates VMs, but AKS nodes are typically managed and ephemeral; replicating them adds complexity and cost, and the solution does not address the App Service frontend or Blob Storage replication efficiently, while active geo-replication for SQL Database is more expensive than an auto-failover group with a secondary database in the same tier.

13
MCQeasy

A company needs to back up an Azure virtual machine that runs a file server. They want to restore individual files quickly without restoring the entire VM. Which backup option should they use?

A.Azure File Sync with cloud tiering.
B.Azure Backup using MARS agent with file and folder backup.
C.Azure Backup for Azure VMs with file-level restore.
D.Azure Backup for Azure VMs with instant restore.
AnswerC

Azure Backup for Azure VMs with file-level restore is the correct choice because it captures full VM snapshots via the Azure Backup extension and stores them in a Recovery Services vault. The file-level restore feature mounts the selected recovery point as a disk (via a temporary recovery VM or an iSCSI target) so you can browse the file system and recover individual files or folders without restoring the entire virtual machine. This provides the granularity you need—backing up the whole Azure VM while still enabling point-in-time file recovery. It also supports both Windows and Linux VMs through a simple portal workflow or PowerShell.

Why this answer

Azure Backup for Azure VMs with file-level restore (option C) is correct because it allows you to mount the VM's backup as a drive on a designated recovery machine using iSCSI, enabling you to browse and copy individual files without restoring the entire VM. This meets the requirement for quick, granular file recovery from a VM backup.

Exam trap

The trap here is confusing 'instant restore' (which speeds up full VM recovery) with 'file-level restore' (which provides granular file access from a VM backup), leading candidates to pick option D when they need individual file recovery.

How to eliminate wrong answers

Option A is wrong because Azure File Sync with cloud tiering is a synchronization and caching solution for on-premises file servers, not a backup service; it does not provide point-in-time restore of individual files from a VM backup. Option B is wrong because the MARS agent with file and folder backup is designed for on-premises Windows servers or Azure VMs running Windows, but it requires installing the agent inside the VM and does not leverage the native Azure VM backup chain; it also cannot restore files from a VM-level backup snapshot. Option D is wrong because Azure Backup for Azure VMs with instant restore refers to the ability to restore a full VM quickly from a snapshot without waiting for vault transfer, but it does not provide file-level granularity; you would still need to restore the entire VM or use file-level restore to access individual files.

14
MCQeasy

A retail company runs its e-commerce platform on Azure VMs. The application uses Azure SQL Database. You are designing a business continuity plan. The company wants to minimize recovery time for a regional outage. Which Azure service should you use to replicate the VMs to a secondary region?

A.Azure Traffic Manager
B.Azure Backup
C.Azure Load Balancer
D.Azure Site Recovery
AnswerD

Azure Site Recovery is the correct service for this scenario because it orchestrates continuous, asynchronous replication of Azure VM disks to a secondary region, enabling a low Recovery Point Objective (RPO) of a few seconds and a Recovery Time Objective (RTO) of minutes. It captures disk changes and can generate application-consistent recovery points, then provides one-click planned or unplanned failover, test failover, and failback. This makes Site Recovery the Azure-native solution for ensuring the e-commerce platform can be brought online in a secondary region after a disaster, which matches the requirement to replicate VMs.

Why this answer

Azure Site Recovery (ASR) orchestrates replication, failover, and failback of Azure VMs from a primary to a secondary region, enabling rapid recovery during a regional outage. It provides continuous replication with a recovery point objective (RPO) of seconds and a recovery time objective (RTO) of minutes, directly meeting the requirement to minimize recovery time for the e-commerce platform's VMs.

Exam trap

The trap here is that candidates often confuse Azure Backup's point-in-time restore capability with Site Recovery's continuous replication and orchestrated failover, mistakenly thinking backups alone can achieve the low RTO required for a regional disaster.

How to eliminate wrong answers

Option A is wrong because Azure Traffic Manager is a DNS-based traffic load balancer that distributes incoming traffic across endpoints, but it does not replicate or protect VM state or data; it only routes users to healthy endpoints. Option B is wrong because Azure Backup provides crash-consistent or application-consistent backups to a Recovery Services vault, but it is designed for point-in-time restore and long-term retention, not for continuous replication with low RTO for a full regional failover. Option C is wrong because Azure Load Balancer distributes network traffic within a region or across availability zones, but it does not replicate VMs or their data to a secondary region; it operates at Layer 4 and has no replication or disaster recovery capability.

15
Multi-Selecthard

Which THREE of the following are required components for a disaster recovery solution using Azure Site Recovery for on-premises Hyper-V VMs?

Select 3 answers
A.A Recovery Services vault in the target Azure region.
B.A replication policy that defines retention and recovery points.
C.The Azure Site Recovery Provider installed on each Hyper-V host.
D.Azure Backup Server installed on-premises.
E.An ExpressRoute connection from on-premises to Azure.
AnswersA, B, C

The Recovery Services vault in the target Azure region is the central management and storage container for all Azure Site Recovery (ASR) data. It stores the replication configuration, recovery points, and journaled data that are needed to bring up virtual machines on Azure during failover. Without it, there is no logical destination for the replicated Hyper-V VMs and no coordination point for the replication workflow. Its placement in the target region is critical because replication data always flows from on-premises to that region, and failover must be able to occur there.

Why this answer

A Recovery Services vault in the target Azure region is required because it serves as the central management and storage container for replication data, configuration settings, and recovery points. Azure Site Recovery (ASR) uses this vault to orchestrate replication, failover, and failback for on-premises Hyper-V VMs to Azure. Without a vault in the target region, there is no destination to store replicated data or manage the recovery process.

Exam trap

The trap here is that candidates often confuse Azure Site Recovery with Azure Backup, assuming that Azure Backup Server (MABS) is needed for replication, when in fact ASR is a separate service with its own provider and does not require any backup server.

16
MCQmedium

A company uses Azure SQL Database for a critical OLTP workload. They need a disaster recovery solution that automatically fails over to a secondary region with an RPO of 5 seconds and an RTO of 1 hour. What should they implement?

A.Azure SQL Database zone-redundant configuration
B.Azure SQL Database active geo-replication
C.Azure SQL Database auto-failover groups
D.Azure SQL Managed Instance failover groups
AnswerC

Auto-failover groups replicate databases to a secondary region and provide a listener endpoint that redirects connections automatically during an outage. This delivers the required sub-five-second RPO and one-hour RTO without manual intervention, unlike geo-restore or active geo-replication alone.

Why this answer

Auto-failover groups in Azure SQL Database provide automatic failover across regions, leveraging active geo-replication under the hood. This combination achieves an RPO of up to 5 seconds (from active geo-replication) and an RTO of 1 hour (from the auto-failover group). Active geo-replication alone does not automate failover, which is required for the disaster recovery solution.

Zone-redundant configuration protects only within a region, not cross-region. Managed Instance failover groups are for Azure SQL Managed Instance, not for Azure SQL Database, and have different RPO/RTO characteristics.

Exam trap

The trap is that candidates may pick active geo-replication (option B) thinking it provides automatic failover, but it only replicates data. The automatic failover capability is provided by auto-failover groups (option C). The question requires both the RPO from replication and the RTO from automatic failover, so auto-failover groups are the correct answer.

How to eliminate wrong answers

Option A is wrong because zone-redundant configuration protects against datacenter failures within a single region, not against a regional disaster, and does not provide cross-region failover or meet the RPO/RTO requirements. Option C is wrong because auto-failover groups use active geo-replication under the hood but add group-level failover orchestration; however, the question asks what to implement, and active geo-replication is the underlying technology that directly provides the specified RPO of 5 seconds and RTO of 1 hour, while auto-failover groups are an optional management layer. Option D is wrong because Azure SQL Managed Instance failover groups are designed for managed instances, not for Azure SQL Database single databases or elastic pools, and the question specifies Azure SQL Database.

17
MCQeasy

You are designing a business continuity solution for a mission-critical Azure Kubernetes Service (AKS) cluster. The cluster hosts a stateful application that uses Azure Disks for persistent volumes. You need to ensure that the application can be recovered in a secondary region within 1 hour of a regional failure. What should you use to replicate the persistent volumes?

A.Azure Disk Backup with geo-redundant storage
B.Azure Backup with disk snapshot policies
C.Azure File Sync to replicate the disk content
D.Azure Site Recovery with replication of the AKS node VMs and attached disks
AnswerD

Azure Site Recovery with replication of the AKS node VMs and attached disks continuously replicates the entire VM and its managed disks to the secondary region, maintaining a ready-to-start copy that can be failed over within a defined RPO and RTO. It provides orchestrated failover, recovery plans, and test failover capabilities, allowing you to safely validate the DR process. While you may need to redeploy or reconfigure the AKS control plane after failover, the replicated node disks ensure your applications' state and data are present, making ASR the only option here that truly delivers a business continuity DR mechanism.

Why this answer

Azure Site Recovery (ASR) can replicate Azure VMs and their attached managed disks to a secondary region. For an AKS cluster, replicating the node VMs and their attached Azure Disks ensures that the persistent volumes (backed by Azure Disks) are available in the secondary region. Combined with AKS cluster deployment in the secondary region, this meets the 1-hour recovery time objective (RTO) for a stateful application.

Exam trap

The trap here is that candidates often choose Azure Backup or Disk Backup options because they associate 'backup' with disaster recovery, but these solutions lack the continuous replication and automated failover required to meet a 1-hour RTO for stateful workloads.

How to eliminate wrong answers

Option A is wrong because Azure Disk Backup with geo-redundant storage provides backup copies in a paired region but does not support continuous replication or automated failover, making it unsuitable for a 1-hour RTO. Option B is wrong because Azure Backup with disk snapshot policies creates point-in-time snapshots, not continuous replication, and recovery from snapshots typically exceeds 1 hour due to manual restore steps. Option C is wrong because Azure File Sync replicates file shares, not Azure Disks; it cannot replicate the block-level data of a disk attached to an AKS node.

18
MCQmedium

Your company has a hybrid identity solution with Microsoft Entra ID Connect syncing on-premises Active Directory to Microsoft Entra ID. You need to design a business continuity solution for the identity service in case of an on-premises outage. The solution must allow users to authenticate and access cloud applications even if the on-premises domain controllers are unavailable. Which feature should you enable?

A.Federation with AD FS in a secondary on-premises site
B.Password hash synchronization
C.Seamless Single Sign-On
D.Pass-through authentication with an agent in a secondary on-premises site
AnswerB

Password hash synchronization (PHS) is the only option that meets the requirement for pure cloud authentication without any on-premises runtime dependency. Azure AD Connect synchronizes a SHA256 hash of the user's AD password (derived from the MD4 hash) to Azure AD; at sign-in, Azure AD validates the credentials locally in the cloud with no call back to on-premises domain controllers. This eliminates the need for on-premises servers during authentication, while still allowing Azure AD to enforce conditional access and other cloud policies.

Why this answer

Password hash synchronization (PHS) is the correct choice because it synchronizes password hashes from on-premises Active Directory to Microsoft Entra ID, enabling cloud authentication even when on-premises domain controllers are unavailable. During an on-premises outage, users can still authenticate against Entra ID using their synced credentials, ensuring continued access to cloud applications without dependency on local infrastructure.

Exam trap

The trap here is that candidates often confuse Seamless SSO or Pass-through authentication as providing offline authentication, but neither works without on-premises infrastructure, whereas password hash synchronization is the only option that enables cloud authentication independently of on-premises domain controllers.

How to eliminate wrong answers

Option A is wrong because federation with AD FS in a secondary on-premises site still relies on on-premises infrastructure; if the primary site fails, the secondary site must be operational, and AD FS itself introduces additional complexity and dependency on local servers. Option C is wrong because Seamless Single Sign-On (SSO) is a feature that provides automatic sign-in when users are on corporate devices connected to the corporate network, but it does not provide authentication during an on-premises outage—it still requires the password hash or other authentication method to be validated. Option D is wrong because Pass-through authentication (PTA) requires an agent installed on-premises to validate credentials against on-premises Active Directory; if the on-premises domain controllers are unavailable, the PTA agent cannot authenticate users, even if a secondary site agent exists, unless that secondary site is also fully operational.

19
Multi-Selectmedium

Which TWO Azure services can be used to automatically redirect traffic to an alternate region in the event of a regional outage? (Choose two.)

Select 2 answers
A.Azure Application Gateway
B.Azure Load Balancer
C.Azure Traffic Manager
D.Azure DNS
E.Azure Front Door
AnswersC, E

Azure Traffic Manager provides DNS-based global load balancing, using priority or performance routing to fail over to an alternate region when health probes detect an outage. This satisfies the stem's requirement for automatic redirection during a regional outage, since DNS responses point clients to a healthy regional endpoint.

Why this answer

Azure Traffic Manager (C) is a DNS-based global traffic load balancer that can route users to endpoints in different regions and, with priority routing plus endpoint monitoring, automatically fail over to an alternate region when the primary region's endpoint becomes unhealthy. Azure Front Door (E) is a global Layer 7 entry point that uses anycast, health probes, and origin groups to detect a regional outage and automatically redirect traffic to a healthy origin in another region. Azure Application Gateway (A) is a regional Layer 7 load balancer, so it can distribute traffic only among backends within its own region and cannot by itself redirect across regions during a regional outage.

Azure Load Balancer (B) is a regional Layer 4 load balancer scoped to a single region and has no global failover capability. Azure DNS (D) is a general-purpose authoritative DNS hosting service; it does not provide built-in health probing or automatic regional failover routing on its own.

Exam trap

The trap here is that candidates confuse regional load balancers (Application Gateway, Load Balancer) with global traffic routing services, forgetting that only DNS-based or Anycast-based services (Traffic Manager, Front Door) can redirect traffic across regions during an outage.

20
MCQhard

A company runs a multi-tier application on Azure VMs in the West US region. The application has web, application, and database tiers. They want to use Azure Site Recovery for disaster recovery to East US. They need to ensure that after failover, the web tier starts first, then the application tier, and finally the database tier after a consistency check. They also need to be able to perform non-disruptive DR drills. Which Azure Site Recovery capabilities should they use together?

A.Create a recovery plan with custom groups and scripts for startup order, and use test failover for DR drills
B.Use Azure Backup for the VMs and restore them in order after failover
C.Use an availability set to control startup order and use disaster recovery drills in a separate VNet
D.Use Azure Traffic Manager to route traffic after failover and manually start VMs in order
AnswerA

Azure Site Recovery recovery plans are the intended orchestration mechanism for multi-tier DR: you can define custom groups for application tiers and insert pre/post scripts (PowerShell or Azure Automation runbooks) so that VMs start in dependency order (e.g., database before web). Test failover executes these plans in an isolated test VNet with cloned recovery points, providing a non-disruptive, repeatable drill that validates the entire startup sequence without touching production.

Why this answer

Azure Site Recovery (ASR) recovery plans allow you to define custom groups and scripts to control the startup order of VMs after failover. By placing the web, application, and database tiers into separate groups with pre- and post-actions (e.g., PowerShell scripts), you can ensure the web tier starts first, then the application tier, and finally the database tier after a consistency check. ASR's test failover capability performs a non-disruptive DR drill by creating isolated copies of VMs in a separate VNet without impacting the production environment.

Exam trap

The trap here is that candidates may confuse Azure Backup's restore capabilities with ASR's orchestrated failover, or assume that availability sets or Traffic Manager can control startup sequencing, when only ASR recovery plans with custom groups and scripts provide the required ordered startup and non-disruptive DR drill functionality.

How to eliminate wrong answers

Option B is wrong because Azure Backup is designed for long-term retention and point-in-time restore, not for orchestrating multi-tier application startup order or performing non-disruptive DR drills with failover sequencing. Option C is wrong because availability sets control VM placement for high availability within a region, not startup order after failover, and they do not provide DR drill capabilities. Option D is wrong because Azure Traffic Manager handles DNS-based traffic routing, not VM startup sequencing, and manually starting VMs in order does not provide automated, scriptable orchestration or non-disruptive DR drills.

21
MCQhard

You are designing a high-availability solution for a stateful application that uses Azure NetApp Files (ANF) for persistent storage. The application must withstand a zonal failure within a region. What should you do?

A.Use Azure Files with zone-redundant storage (ZRS) and SMB multi-channel.
B.Use Azure NetApp Files cross-zone replication to replicate data between availability zones.
C.Use Azure Backup for ANF with daily snapshots stored in a different zone.
D.Deploy the application in an Availability Set and use ANF volumes with zone-redundant storage (ZRS).
AnswerB

Azure NetApp Files cross-zone replication continuously asynchronously replicates volume data from a primary ANF volume in one availability zone to a secondary volume in another zone, using NetApp SnapMirror technology. If the primary zone fails, you can mount the destination volume in the secondary zone, providing a much lower RTO than backup and true zonal resilience. This directly meets the high-availability requirement while staying within the ANF service, and the RPO is typically in the range of a few minutes.

Why this answer

Azure NetApp Files cross-zone replication asynchronously replicates volume data from a source zone to a destination zone within the same region, enabling failover if the primary zone fails. This meets the requirement for zonal failure tolerance while preserving the stateful application's persistent storage. Other options either lack native zone-redundant support for ANF or provide only backup, not continuous replication.

Exam trap

The trap here is that candidates confuse Azure Files ZRS (which is zone-redundant but not ANF) with Azure NetApp Files, or assume that backup snapshots alone provide high availability for zonal failures, when in fact continuous replication is required for minimal downtime and data loss.

How to eliminate wrong answers

Option A is wrong because Azure Files with ZRS provides zone-redundant storage but is a different service than Azure NetApp Files; the question specifically requires ANF for persistent storage, and Azure Files does not support the same protocols (e.g., NFSv3, SMB) or performance characteristics as ANF. Option C is wrong because Azure Backup for ANF with daily snapshots stored in a different zone provides point-in-time recovery, not continuous replication; it cannot achieve the required recovery point objective (RPO) for zonal failure and does not enable automatic failover. Option D is wrong because Azure NetApp Files does not support zone-redundant storage (ZRS); ANF volumes are zonal resources, and Availability Sets are for VMs, not storage; combining them does not provide zone-level redundancy for the storage layer.

22
MCQeasy

A company uses Azure Backup to protect their critical Azure VMs. An administrator accidentally deleted a file from one of the VMs. They need to restore that specific file quickly without restoring the entire VM. Which Azure Backup feature should they use?

A.Azure Backup full VM restore
B.Azure Backup file recovery
C.Azure Site Recovery
D.Azure Storage snapshots
AnswerB

Azure Backup file recovery is the correct feature because it directly addresses the need for rapid, granular restoration. From the Recovery Services vault, you select a restore point and run a script that mounts that backup as an iSCSI drive on a chosen or existing VM, allowing you to browse and copy specific files or folders instantaneously. This read-only mount works for both Windows and Linux VMs and avoids any full VM restore overhead, making it the fastest way to recover a single file.

Why this answer

Azure Backup's file recovery feature allows you to mount a recovery point as a drive on the VM (or another machine) using iSCSI, enabling you to browse and copy individual files without restoring the entire VM. This is the correct choice because it meets the requirement for a quick, granular restore of a single deleted file.

Exam trap

The trap here is that candidates may confuse Azure Backup's file recovery with Azure Site Recovery, thinking both provide granular restore, but Site Recovery is for replication and failover, not for point-in-time file recovery from backups.

How to eliminate wrong answers

Option A is wrong because full VM restore would recover the entire virtual machine, which is unnecessary and time-consuming for restoring a single file. Option C is wrong because Azure Site Recovery is designed for disaster recovery and replication of entire workloads to a secondary region, not for granular file-level recovery from backup snapshots. Option D is wrong because Azure Storage snapshots are a feature of Azure Storage accounts (blobs, files, disks) and are not directly integrated with Azure Backup's VM-level recovery points; they also require manual management and do not provide the iSCSI mount capability for file-level recovery.

23
MCQhard

A company runs a mission-critical application on Azure virtual machines (VMs) in the West US region. The application consists of multiple VMs that must be recovered in a specific order during a disaster: database VM first, then application VMs, then web VMs. They also require that after failover to East US, the VMs retain their private IP addresses to avoid DNS updates. The recovery point objective (RPO) is 5 minutes and recovery time objective (RTO) is 30 minutes. The company needs to perform quarterly disaster recovery tests without impacting production. Which combination of Azure Site Recovery features should they configure?

A.Use crash-consistent replication, recovery plans with manual ordering, and target network with same IP address range
B.Use app-consistent replication, recovery plans with pre/post scripts for ordering, and static IP address assignment in failover settings
C.Use multi-VM consistency groups, recovery plans with automation runbooks, and Azure Traffic Manager to redirect traffic
D.Use application-consistent replication, recovery plans with pre/post scripts for ordering, and target network with different IP address range and DNS updates
AnswerB

App-consistent replication uses VSS on Windows or equivalent application quiescing on Linux to flush memory and pending I/O, producing a recovery point that is both VM-consistent and application-consistent, which is essential for a mission-critical database and supports an RPO of seconds. Recovery plans with pre/post scripts automate the ordering of failover steps, such as starting dependent applications or running validation scripts, eliminating manual sequencing delays. Static IP address assignment in the failover settings republishes the original private IPs on the target subnet, satisfying the explicit IP-retention requirement without DNS changes. This combination delivers the required data integrity, automated orchestration, and network continuity.

Why this answer

The requirement for an RPO of 5 minutes and RTO of 30 minutes necessitates application-consistent replication, which ensures database and application integrity. The need to recover VMs in a specific order is met by recovery plans with pre/post scripts, which allow custom actions (e.g., starting the database VM first, then application, then web). Static IP address assignment in failover settings ensures that VMs retain their private IP addresses after failover to East US, avoiding DNS updates.

Exam trap

The trap here is that candidates often confuse crash-consistent replication (which is faster but not application-safe) with application-consistent replication, or they assume that manual ordering in recovery plans is sufficient without realizing that pre/post scripts are required for complex multi-tier dependencies and that static IP assignment is needed to retain IP addresses across regions.

How to eliminate wrong answers

Option A is wrong because crash-consistent replication cannot achieve a 5-minute RPO for a mission-critical application with database VMs, as it does not guarantee application consistency; also, manual ordering in recovery plans is not sufficient for complex multi-tier recovery sequences. Option C is wrong because multi-VM consistency groups ensure crash consistency across VMs but do not provide the application-consistent replication needed for the 5-minute RPO, and Azure Traffic Manager is for traffic routing, not for retaining private IP addresses or ordering recovery. Option D is wrong because using a target network with a different IP address range and DNS updates contradicts the requirement to retain private IP addresses to avoid DNS updates.

24
MCQmedium

A company runs a global e-commerce platform on Azure VMs in a single region. They need to replicate the VMs to a secondary region for disaster recovery. Recovery must be possible within 30 minutes of a failure. The VMs run custom software that must be started in a specific order (database tier before web tier). Which Azure service should they use to meet both the replication and orchestration requirements?

A.Azure Site Recovery with recovery plans
B.Azure Backup with cross-region restore
C.Azure Migrate with replication
D.Azure Automation runbooks
AnswerA

Azure Site Recovery performs continuous block-level replication of Azure VMs to a secondary region, providing a low RPO; recovery plans group VMs into logical tiers, specify failover order, and can execute pre/post scripts, which lets the whole e-commerce stack fail over predictably within a 30-minute RTO. Recovery plans also allow manual or test failovers, so the response is organized rather than ad hoc.

Why this answer

Azure Site Recovery (ASR) with recovery plans is the correct choice because it provides both VM replication to a secondary region and the ability to orchestrate the startup order of VMs. Recovery plans allow you to group VMs into tiers (e.g., database and web) and define dependencies, ensuring the database tier starts before the web tier. ASR meets the 30-minute recovery time objective (RTO) by enabling failover to the secondary region within that timeframe.

Exam trap

The trap here is that candidates often confuse Azure Backup (which is for data protection and long-term retention) with Azure Site Recovery (which is for replication and failover), and overlook the orchestration requirement that only recovery plans can fulfill.

How to eliminate wrong answers

Option B is wrong because Azure Backup with cross-region restore is designed for long-term data retention and point-in-time recovery, not for orchestrating multi-tier application startup order or meeting a 30-minute RTO for full VM failover. Option C is wrong because Azure Migrate is a tool for assessing and migrating on-premises workloads to Azure, not for ongoing replication or disaster recovery orchestration. Option D is wrong because Azure Automation runbooks can execute scripts to start VMs in order, but they do not provide the underlying VM replication to a secondary region, which is required for disaster recovery.

25
MCQmedium

Your company runs a critical e-commerce application on Azure Virtual Machines (VMs) in a single region. You need to design a disaster recovery (DR) solution that meets a recovery point objective (RPO) of 15 minutes and a recovery time objective (RTO) of 1 hour for the application tier. The application uses Azure SQL Database (single database). Which combination of Azure services should you recommend to meet the RPO and RTO?

A.Use Azure Site Recovery for VMs and Azure SQL Database read-scale replicas
B.Use Azure Backup for VM replication and Azure SQL Database auto-failover groups
C.Use Azure Front Door with regional load balancing and Azure SQL Database geo-restore
D.Use Azure Site Recovery for VM replication to a secondary region and Azure SQL Database active geo-replication
AnswerD

Azure Site Recovery continuously replicates Azure VMs to a secondary region, providing crash-consistent and app-consistent recovery points with an RPO typically under 15 minutes, and it supports orchestrated failover to meet the required RTO. Azure SQL Database active geo-replication asynchronously replicates transactions to a fully readable secondary database in another region, offering an RPO of about 5 seconds and manual failover capability with minimal recovery time. Together, these services deliver the low RPO/RTO needed for a critical online transaction processing application, making this the correct solution.

Why this answer

Azure Site Recovery provides VM replication to a secondary region with RPO as low as 15 seconds and RTO typically under 1 hour, meeting the 15-minute RPO and 1-hour RTO. Azure SQL Database active geo-replication creates a readable secondary database in another region with an RPO of 5 seconds or less and supports manual failover within minutes, satisfying the stated RPO and RTO. This combination ensures both compute and database tiers can be recovered in the secondary region within the required timeframes.

Exam trap

The trap here is that candidates often confuse Azure Backup (a backup service with longer RPO/RTO) with Azure Site Recovery (a replication service for DR), or they mistakenly think read-scale replicas or geo-restore can meet aggressive RPO/RTO requirements when they are designed for different purposes.

How to eliminate wrong answers

Option A is wrong because Azure SQL Database read-scale replicas are designed for read-only workload offloading, not disaster recovery; they do not support failover and cannot meet the RPO/RTO for a single database DR scenario. Option B is wrong because Azure Backup for VM replication is a backup solution, not a replication service, and its RPO is typically 12-24 hours with RTO measured in hours or days, failing the 15-minute RPO and 1-hour RTO. Option C is wrong because Azure Front Door with regional load balancing provides traffic routing and health probing but does not replicate VMs or databases; Azure SQL Database geo-restore restores from backups with an RPO of 1 hour and RTO of 12-24 hours, which does not meet the required 15-minute RPO and 1-hour RTO.

26
MCQmedium

A company runs a critical application on Azure VMs in a single region. The application uses Azure SQL Database as its data store. The company needs a disaster recovery solution that can fail over the entire application stack (VMs and database) to another region with a Recovery Point Objective (RPO) of 5 minutes and a Recovery Time Objective (RTO) of 1 hour. The solution must be automated and minimize manual steps. Which combination of Azure services should they implement?

A.Azure Site Recovery for VMs and active geo-replication with auto-failover groups for Azure SQL Database
B.Azure Backup for VMs and Azure SQL Database backup to another region
C.Azure Site Recovery for VMs and Azure DNS for database failover
D.Azure Load Balancer for VMs and Azure SQL Database failover groups
AnswerA

Azure Site Recovery continuously replicates the source VMs to the secondary region using a recovery point objective (RPO) as low as a few seconds, easily satisfying the 5-minute RPO requirement, and its recovery plans orchestrate compute failover to meet the 1-hour RTO. Active geo-replication for Azure SQL Database maintains a readable secondary replica in the paired region and, when combined with an auto-failover group, automatically redirects connections to the secondary on outage with an RPO of 5 seconds and an RTO typically under 1 hour. Together, these two services provide a cohesive disaster recovery solution for both the IaaS VM tier and the PaaS database tier, with asynchronous replication that meets the stated recovery objectives.

Why this answer

Azure Site Recovery (ASR) orchestrates replication and automated failover of Azure VMs to a secondary region, meeting the RTO of 1 hour. Active geo-replication with auto-failover groups for Azure SQL Database provides a readable secondary replica in another region with an RPO of 5 seconds (well under the 5-minute requirement) and enables automatic failover without manual intervention. Together, they automate the entire application stack failover, minimizing manual steps.

Exam trap

The trap here is that candidates often confuse Azure Backup (which is for data recovery, not failover) with Azure Site Recovery (which is for full-stack disaster recovery), or they assume DNS or load balancers alone can handle database failover without understanding that database replication is required first.

How to eliminate wrong answers

Option B is wrong because Azure Backup for VMs and Azure SQL Database backup to another region provides point-in-time restore but does not support automated failover; restoring from backup would take hours, exceeding the 1-hour RTO, and the RPO would be limited to the backup schedule (typically 24 hours). Option C is wrong because Azure DNS for database failover does not handle database replication or failover; it only manages DNS records, leaving the database unreplicated and requiring manual steps to redirect traffic, which fails the automation requirement. Option D is wrong because Azure Load Balancer distributes traffic but does not replicate VMs or databases; it cannot fail over VMs to another region, and Azure SQL Database failover groups alone (without active geo-replication) do not provide the required RPO of 5 minutes—failover groups require geo-replication to be configured separately.

27
MCQmedium

Refer to the exhibit. You deploy an Azure SQL Database with a secondary replica in another region using the ARM template shown. You need to ensure that the database can fail over automatically with zero data loss. What is missing?

A.Configure long-term backup retention.
B.Disable readScaleOut on the primary database.
C.Create a failover group that includes both databases.
D.Set zoneRedundant to true on the primary database.
AnswerC

Creating a failover group that includes both the primary and secondary databases establishes an active geo-replication relationship and exposes a single read-write listener endpoint plus a read-only endpoint. When the primary database experiences an outage, the group automatically initiates failover to the secondary, and applications can reconnect using the same group-level FQDN (or the FailoverPartner modifier) without code changes. This is the correct Azure SQL Database feature for managing automatic, cross-region failover with near-zero data loss based on the configured grace period.

Why this answer

A failover group is required to enable automatic failover between the primary and secondary replicas in Azure SQL Database. Without a failover group, the secondary replica exists as a readable copy but cannot automatically take over during a disaster. The failover group also supports the ability to achieve zero data loss by using the 'GracePeriodWithDataLoss' setting or by ensuring synchronous replication is configured, which is part of the failover group's properties.

Exam trap

The trap here is that candidates often confuse a geo-replicated secondary replica (which only provides readable standby) with a failover group (which adds automatic failover and a listener endpoint), leading them to think the secondary replica alone is sufficient for automatic failover.

How to eliminate wrong answers

Option A is wrong because long-term backup retention (LTR) is for point-in-time restore of backups beyond the default retention period, not for automatic failover or zero data loss. Option B is wrong because disabling readScaleOut on the primary database only affects whether the secondary replica is used for read-only workloads; it does not impact automatic failover or data loss prevention. Option D is wrong because setting zoneRedundant to true on the primary database provides high availability within a single region by replicating across availability zones, but it does not enable cross-region automatic failover or guarantee zero data loss across regions.

28
MCQhard

Refer to the exhibit. A role assignment has a condition that controls blob deletion. A user assigned this role tries to delete a blob with tag 'Project' set to 'ProjectB'. What will happen?

A.The deletion is allowed because the condition only applies to write operations
B.The deletion is allowed because the condition does not affect blob deletion
C.The deletion is denied because the blob does not have the required tag
D.The deletion is denied because the condition version is 2.0 and not supported
AnswerC

The role assignment condition permits blob deletion only when the blob carries the required tag value. Because the blob's 'Project' tag is set to 'ProjectB' rather than the value the condition expects, the condition evaluates false and the delete operation is blocked.

Why this answer

The role assignment condition likely requires the blob to have the tag 'Project' set to a specific value (e.g., 'ProjectA'). Since the blob in question has the tag 'Project' set to 'ProjectB', the condition is not satisfied, and the deletion is denied. Option C correctly identifies this mismatch.

Exam trap

The trap is that candidates may focus on the action type or condition version, but the key is the tag value mismatch. The condition requires a specific tag value, and the blob has a different one, leading to denial.

How to eliminate wrong answers

Option A is wrong because the condition explicitly targets the delete action (Microsoft.Storage/storageAccounts/blobServices/containers/blobs/delete), not just write operations, so it does apply to blob deletion. Option B is wrong because the condition directly affects blob deletion by requiring a specific tag value; it does not leave deletion unaffected. Option D is wrong because condition version 2.0 is fully supported in Azure RBAC for storage actions, and the version does not cause denial.

29
MCQmedium

A company runs a critical SQL Server database on an Azure virtual machine in the West US region. They need a disaster recovery solution that replicates the database to a secondary region (East US) with a recovery point objective (RPO) of 15 minutes and a recovery time objective (RTO) of 2 hours. The solution must also support non-disruptive disaster recovery drills. The company currently uses SQL Server Standard Edition. Which Azure service should they implement?

A.Azure Site Recovery
B.SQL Server Always On Availability Groups
C.Azure Backup with cross-region restore
D.Azure SQL Database geo-replication
AnswerA

Azure Site Recovery replicates the entire Azure VM at the block level to a secondary region, achieving an RPO as low as 30 seconds for SQL Server when app-consistent snapshots are enabled through the SQL Server VSS writer. It provides a dedicated test failover capability that provisions the replica in an isolated VNet without any impact on production, fully satisfying the non-disruptive drill requirement. ASR works with SQL Server Standard Edition on IaaS and supports orchestrated recovery plans for multi-tier failover, making it the only option here that meets all stated RPO/RTO criteria with minimal operational overhead.

Why this answer

Azure Site Recovery (ASR) replicates the entire VM, including the SQL Server database, to the secondary region with an RPO as low as 15 minutes and an RTO of 2 hours when using a recovery plan. It supports non-disruptive disaster recovery drills by allowing test failovers that run in an isolated network without impacting the production environment. This makes ASR the correct choice for a SQL Server Standard Edition VM requiring cross-region DR with drills.

Exam trap

The trap here is that candidates often choose SQL Server Always On Availability Groups without realizing that Standard Edition lacks the necessary features (e.g., readable secondaries, multi-database support) to meet the RPO/RTO and drill requirements, or they mistakenly think Azure SQL Database geo-replication can be applied to a SQL Server VM.

How to eliminate wrong answers

Option B is wrong because SQL Server Always On Availability Groups requires SQL Server Enterprise Edition for the advanced features needed to meet the RPO/RTO, and Standard Edition only supports basic availability groups with a single database and no readable secondaries, which cannot achieve the required 15-minute RPO or support non-disruptive drills. Option C is wrong because Azure Backup with cross-region restore provides point-in-time backups with an RPO of typically 12-24 hours (not 15 minutes) and an RTO that can exceed 2 hours due to restore time, plus it does not support live, non-disruptive disaster recovery drills. Option D is wrong because Azure SQL Database geo-replication is a PaaS feature that cannot be applied to a SQL Server running on an Azure VM (IaaS); it only works with Azure SQL Database managed instances or single databases.

30
MCQmedium

A company runs critical Azure VMs. They want to protect against accidental deletion or corruption of data by implementing a retention policy for Azure Backup. They need to keep daily backups for 30 days, weekly backups for 12 weeks, and monthly backups for 12 months. Which Azure Backup feature should they configure?

A.Immutable vault
B.Backup policy with long-term retention
C.Backup tiering
D.Soft delete
AnswerB

A backup policy in Azure Backup is the mechanism that defines both the backup frequency (when recovery points are created) and the retention rules that govern how long each recovery point is kept. By specifying a daily backup with 30 days retention, a weekly backup with 12 weeks retention, and a monthly backup with 12 months retention, the policy can create and automatically prune recovery points according to these exact schedules. This directly satisfies the stated requirement for different retention durations across daily, weekly, and monthly recovery points.

Why this answer

A backup policy with long-term retention (LTR) in Azure Backup allows you to define granular retention rules for daily, weekly, monthly, and yearly backup points. This directly meets the requirement to keep daily backups for 30 days, weekly for 12 weeks, and monthly for 12 months by configuring the retention duration for each frequency in the backup policy.

Exam trap

The trap here is that candidates confuse Immutable vault or Soft delete with retention policies, but those features address data protection from deletion or tampering, not the ability to specify granular retention durations for different backup frequencies.

How to eliminate wrong answers

Option A is wrong because Immutable vault protects backup data from being deleted or overwritten before its retention period expires, but it does not provide the ability to configure different retention durations for daily, weekly, and monthly backups. Option C is wrong because Backup tiering moves older recovery points to a lower-cost storage tier (e.g., from hot to cold or archive), but it does not define or enforce retention durations; it is a cost-optimization feature, not a retention policy. Option D is wrong because Soft delete provides a safety net by retaining deleted backup data for a default period (14 days) to allow recovery from accidental deletion, but it does not allow you to specify custom retention periods like 30 days daily, 12 weeks weekly, or 12 months monthly.

31
Multi-Selecthard

Which THREE of the following are valid strategies for designing a disaster recovery plan for Azure Virtual Desktop? (Choose three.)

Select 3 answers
A.Use Azure Front Door to route RDP traffic to the secondary region
B.Use Azure File Sync to replicate FSLogix profile shares to a secondary region
C.Pre-deploy a secondary host pool in the DR region and use Azure Traffic Manager to redirect connections
D.Rely on Azure Backup to restore session hosts in the secondary region
E.Replicate session host VMs to a secondary region using Azure Site Recovery
AnswersB, C, E

Azure File Sync replicates the file hierarchy from a primary SMB share to a file share in the secondary region, keeping FSLogix profile containers available to users after failover. Because FSLogix profiles are stored as VHDX files in file shares, sync copies them without needing a backup restore, and the DR region's session hosts simply attach to the synced share. This preserves persistent user state and is a valid DR strategy when combined with compute failover.

Why this answer

Option B is correct because Azure File Sync can replicate the SMB file shares that host FSLogix profile containers and Office container VHDX files to a secondary region, giving users access to their profiles during a regional failover. Option C is correct because pre-deploying a secondary host pool in the DR region and using Azure Traffic Manager (or a similar global load balancer) to redirect user connections is a standard AVD multi-region DR pattern that reduces recovery time. Option E is correct because Azure Site Recovery can continuously replicate session host VMs to a secondary region so they can be failed over and brought online as replacement session hosts during a disaster.

Option A is not valid because Azure Front Door does not proxy RDP traffic (TCP 3389); it is an HTTP/HTTPS layer-7 service, and AVD clients connect to the gateway/broker, not through Front Door. Option D is not a valid DR strategy because Azure Backup restores data and VMs but does not provide the low-RTO regional failover or the AVD control-plane/broker redirection needed for a disaster recovery plan.

Exam trap

The trap here is that candidates often confuse Azure Front Door (an HTTP/HTTPS load balancer) with Azure Traffic Manager (a DNS-based traffic router that can handle RDP traffic), leading them to incorrectly select Option A instead of Option C.

32
MCQmedium

Your company runs a critical workload on Azure Virtual Machines in a single region. You need to design a disaster recovery solution that meets a Recovery Point Objective (RPO) of 15 minutes and a Recovery Time Objective (RTO) of 1 hour. The solution should minimize cost. What should you recommend?

A.Configure Azure Backup with geo-redundant storage.
B.Deploy an active-passive pair of VMs using SQL Server Always On availability groups.
C.Use Azure Storage with read-access geo-redundant storage (RA-GRS) and failover the VMs.
D.Implement Azure Site Recovery with replication to a secondary region.
AnswerD

Azure Site Recovery (ASR) is purpose-built for disaster recovery of Azure VMs, replicating the entire VM to a secondary region with an RPO that can be as low as 15 seconds and typically well under the required 15 minutes. It provides crash-consistent and app-consistent snapshot replication, automated failover, failback, and recovery plans, enabling predictable RTO. This makes ASR the correct, cost-effective option that fully satisfies the stated 15-minute RPO requirement.

Why this answer

Azure Site Recovery (ASR) provides continuous replication of Azure VMs to a secondary region, enabling failover within minutes. With replication intervals as low as 30 seconds for crash-consistent and 5 minutes for app-consistent snapshots, it comfortably meets the 15-minute RPO, and the orchestrated failover process can achieve the 1-hour RTO. ASR is the native Azure service designed for this exact scenario, minimizing cost by only charging for replication traffic and storage in the secondary region.

Exam trap

The trap here is that candidates confuse Azure Backup (which is for backup/restore) with Azure Site Recovery (which is for disaster recovery/failover), assuming that geo-redundant storage alone can provide VM-level DR, when in fact it only protects storage data, not compute or application state.

How to eliminate wrong answers

Option A is wrong because Azure Backup is designed for long-term retention and point-in-time restore, not for rapid failover; its RTO is typically measured in hours or days, not 1 hour, and it does not provide continuous replication to meet a 15-minute RPO. Option B is wrong because SQL Server Always On availability groups are a database-level HA/DR solution that only protects SQL Server workloads, not the entire VM or other applications, and it requires significant licensing and infrastructure costs. Option C is wrong because RA-GRS is a storage redundancy option that provides read-only access to data in a secondary region; it does not replicate the VM configuration, operating system, or application state, and failover of VMs is not supported by this service.

33
MCQmedium

A company runs a critical OLTP application on Azure SQL Database in the West US region. They need to ensure business continuity if a regional outage occurs. The solution must have a recovery point objective (RPO) of 5 seconds and a recovery time objective (RTO) of less than 1 hour. They also want to use the secondary region for read-only query offloading. Which Azure SQL Database feature should they enable?

A.Active geo-replication with automatic failover group
B.Geo-restore
C.Azure Site Recovery
D.Read scale-out with manual regional failover
AnswerA

Active geo-replication continuously pushes transactions to a readable secondary in a paired region, achieving a recovery point objective (RPO) of about 5 seconds and an RTO under one hour. When paired with an auto-failover group, outage detection and promotion of the secondary are automated, so the critical OLTP workload can resume without manual intervention and the secondary can also serve read-only queries during normal operation. This combination directly satisfies both the low data-loss and fast-recovery requirements.

Why this answer

Active geo-replication with automatic failover groups is the correct choice because it provides continuous asynchronous data replication to a secondary Azure SQL Database in a paired region, achieving an RPO of 5 seconds and an RTO of under 1 hour. The automatic failover group enables coordinated failover of multiple databases and allows the secondary region to be used for read-only query offloading by connecting with ApplicationIntent=ReadOnly.

Exam trap

The trap here is that candidates confuse geo-restore (backup-based) with active geo-replication (continuous replication), or assume read scale-out can span regions, when in fact it only works within the same Azure region.

How to eliminate wrong answers

Option B (Geo-restore) is wrong because it restores a database from geo-replicated backups with an RPO of 1 hour and an RTO of 12+ hours, failing the 5-second RPO and 1-hour RTO requirements. Option C (Azure Site Recovery) is wrong because it is designed for IaaS VM replication, not for PaaS Azure SQL Database, and cannot meet the 5-second RPO or provide read-only query offloading. Option D (Read scale-out with manual regional failover) is wrong because read scale-out only offloads read-only queries using a readable secondary replica within the same region, not in a secondary region, and manual failover does not meet the automated RTO of under 1 hour.

34
MCQhard

A company runs a critical SAP HANA database on an Azure large instance. They need a disaster recovery solution that provides automatic failover to a secondary region with an RPO of 15 minutes and RTO of 30 minutes. The solution must not require manual intervention to start replication. What should they use?

A.SAP HANA System Replication with HANA Pacemaker
B.Azure Site Recovery with replication policy for SAP HANA
C.Azure NetApp Files with cross-region replication
D.Azure Backup for SAP HANA
AnswerA

SAP HANA System Replication replicates the database at the log and data level from a primary to a secondary node, while the HANA Pacemaker cluster provides cluster orchestration, heartbeat monitoring, and STONITH fencing to automatically promote the secondary when the primary fails. This combination yields near-zero RPO with synchronous replication and automatic RTO in minutes, which is exactly what critical SAP HANA workloads need without manual intervention.

Why this answer

SAP HANA System Replication with HANA Pacemaker is the correct choice because it provides automatic, synchronous or asynchronous replication of SAP HANA data to a secondary region, meeting the RPO of 15 minutes and RTO of 30 minutes. HANA Pacemaker handles automatic failover without manual intervention, ensuring the database is promoted to primary in the disaster recovery region within the required timeframes. This solution is specifically designed for SAP HANA on Azure large instances, offering native integration and support for the required recovery objectives.

Exam trap

The trap here is that candidates often confuse Azure Site Recovery's VM replication with application-consistent replication, but it cannot meet the sub-minute RPO or automatic failover requirements for a critical SAP HANA database without risking data loss or corruption.

How to eliminate wrong answers

Option B is wrong because Azure Site Recovery replicates VMs at the hypervisor level and does not understand SAP HANA database consistency, so it cannot guarantee an RPO of 15 minutes or automatic failover without data corruption. Option C is wrong because Azure NetApp Files cross-region replication operates at the file system level and does not provide application-consistent replication for SAP HANA, nor does it support automatic failover with the required RTO. Option D is wrong because Azure Backup for SAP HANA is a backup solution, not a replication or disaster recovery solution, and cannot achieve an RPO of 15 minutes or automatic failover to a secondary region.

35
MCQmedium

Refer to the exhibit. You are reviewing a backup policy for an Azure VM. The policy is defined using the Azure Backup REST API. What is the maximum number of recovery points that can be retained according to this policy?

A.24
B.17
C.29
D.12
AnswerA

12 weekly (every Mon, Wed, Fri for 12 weeks) + 12 monthly (first Sunday each month for 12 months) = 24 recovery points.

Why this answer

The weekly retention keeps 12 weekly points (count=12, durationType=Weeks). The monthly retention keeps 12 monthly points (count=12, durationType=Months). Instant RP retention adds up to 5 days, but those are additional recovery points not counted in the long-term retention.

So total long-term recovery points = 12 (weekly) + 12 (monthly) = 24. Option A is correct.

36
Multi-Selecthard

A company wants to ensure that their Azure Storage account containing blobs is protected against accidental deletion or corruption. The solution must enable recovery of previous versions up to 30 days. Which TWO features should they enable? (Choose TWO.)

Select 2 answers
A.Blob versioning
B.Blob soft delete
C.Change feed
D.Azure Backup for Azure Blobs
E.Point-in-time restore for Azure Files
AnswersA, B

Blob versioning automatically captures the state of a blob each time it is modified, preserving an accessible copy of every previous version in the same storage account. If the current blob is accidentally overwritten or corrupted, you can promote a prior version to restore the blob without relying on a separate backup service.

Why this answer

Blob versioning automatically maintains previous versions of a blob when it is modified or deleted, enabling recovery of any version from the last 30 days if combined with a lifecycle management policy to retain versions for that period. Blob soft delete protects against accidental deletion by preserving deleted blobs in a soft-deleted state for a specified retention period (up to 30 days), allowing restoration within that window. Together, they provide comprehensive protection against both accidental deletion and corruption.

Exam trap

The trap here is that candidates often confuse Azure Backup for Azure Blobs (a separate backup service) with native blob protection features like versioning and soft delete, or they mistakenly think Change feed provides recovery capabilities when it only logs changes.

37
MCQhard

Refer to the exhibit. An administrator configured Azure Site Recovery replication for a VM using the policy shown. The VM workload is a critical database that requires application-consistent snapshots every 30 minutes to meet compliance. What is the issue with the current configuration?

A.The application-consistent snapshot frequency is 60 minutes, which is too high (should be 30 minutes).
B.The recovery point retention is set too low (1440 minutes).
C.The target region eastus2 is not a valid paired region for the source.
D.The storage account type is Standard_LRS; it should be Premium_LRS.
AnswerA

The Azure Site Recovery replication policy is configured for application-consistent snapshots every 60 minutes. This directly contradicts the compliance requirement for the critical database workload, which mandates application-consistent snapshots every 30 minutes. The policy's application-consistent snapshot frequency setting must be reduced to 30 minutes to meet the specified compliance constraint.

Why this answer

The current policy sets the application-consistent snapshot frequency to 60 minutes, but the compliance requirement demands a snapshot every 30 minutes. Application-consistent snapshots are taken by the Azure Site Recovery mobility service using VSS (Volume Shadow Copy Service) on Windows, and the frequency is configured in the replication policy. Since the requirement is 30 minutes, the policy must be adjusted to match that interval.

Exam trap

The trap here is that candidates may confuse crash-consistent snapshots (which can be as frequent as every few seconds) with application-consistent snapshots, or assume that retention or storage type is the root cause, when the actual constraint is the snapshot frequency mismatch.

How to eliminate wrong answers

Option B is wrong because the recovery point retention of 1440 minutes (24 hours) is a typical and acceptable value for critical workloads; there is no indication that it is too low. Option C is wrong because eastus2 is a valid paired region for eastus (the source region is not specified, but eastus2 is commonly paired with eastus in Azure's regional pairs). Option D is wrong because the storage account type (Standard_LRS vs Premium_LRS) affects performance and cost, not the ability to meet the 30-minute snapshot compliance requirement; the issue is purely about snapshot frequency, not storage tier.

38
MCQmedium

A company runs a critical application on Azure Virtual Machines in a single availability set. They want to protect against an entire Azure region failure. They need a recovery time objective (RTO) of 30 minutes and a recovery point objective (RPO) of 15 minutes. Which solution should they use?

A.Azure Backup for VMs with geo-redundant backup storage.
B.Azure Site Recovery to another region.
C.Deploy VMs in an availability zone within the same region.
D.Use Azure managed disks with geo-replication (LRS to GRS).
AnswerB

Azure Site Recovery replicates VMs continuously to a secondary region. It can achieve RPO as low as 15 seconds (with app-consistent snapshots) and RTO of minutes (30 minutes is typical). It supports planned and unplanned failover.

Why this answer

Azure Site Recovery (ASR) provides orchestrated replication, failover, and failback of Azure VMs to a secondary region, enabling a recovery time objective (RTO) of 30 minutes and a recovery point objective (RPO) of 15 minutes as required. ASR replicates VM disks continuously to the target region, and in a regional failure, you can initiate a planned or unplanned failover to bring up the application within the specified RTO/RPO. This is the only option that offers both cross-region disaster recovery and the granular recovery objectives stated.

Exam trap

The trap here is that candidates often confuse Azure Backup (which provides long-term retention with geo-redundancy) with Azure Site Recovery (which provides near-synchronous replication and automated failover), leading them to select Option A despite its inability to meet the strict RTO/RPO requirements.

How to eliminate wrong answers

Option A is wrong because Azure Backup with geo-redundant storage (GRS) is designed for long-term backup and restore, not for rapid failover; its typical RTO is hours or days, not 30 minutes, and it does not support orchestrated cross-region failover. Option C is wrong because deploying VMs in an availability zone within the same region protects against datacenter failures, not an entire Azure region failure, and thus does not meet the requirement for cross-region disaster recovery. Option D is wrong because Azure managed disks with geo-replication (LRS to GRS) is not a supported feature—managed disks use locally redundant storage (LRS) by default and cannot be directly geo-replicated; the misconception is that GRS applies to disks, but it applies only to storage accounts, and even then it does not provide the orchestrated failover or RTO/RPO guarantees of Azure Site Recovery.

39
MCQeasy

A company stores backup data for Azure VMs in a Recovery Services vault. They need to ensure that the backup data is protected from accidental deletion and remains available even if the entire Azure region fails. What should you configure?

A.Assign Azure RBAC roles to limit access to the vault.
B.Enable soft delete in the vault and use geo-redundant storage (GRS).
C.Enable immutable storage for the vault.
D.Enable locally redundant storage (LRS) for the vault.
AnswerB

Soft delete for a Recovery Services vault retains accidentally deleted backup data for an additional 14 days after deletion, allowing it to be recovered before permanent purge; this directly protects against accidental or malicious deletion of backup items. Geo-redundant storage (GRS) copies backup data to a paired Azure region, so even if the primary region's datacenter fails, the backup data remains available for restore from the secondary region. Together, these two controls address both deletion protection and cross-region disaster recovery.

Why this answer

Enabling soft delete protects backup data from accidental deletion by retaining deleted data for a default retention period of 14 days, allowing recovery. Using geo-redundant storage (GRS) replicates vault data to a paired secondary Azure region, ensuring availability even if the entire primary region fails. Together, these features meet both protection and regional failover requirements.

Exam trap

The trap here is that candidates often confuse immutable storage (a Blob Storage feature) with backup vault protection, or think RBAC alone prevents deletion, overlooking that soft delete and GRS are the specific Azure Backup mechanisms for deletion protection and regional resilience.

How to eliminate wrong answers

Option A is wrong because Azure RBAC roles control access permissions but do not protect against accidental deletion by authorized users or provide geo-redundancy for regional failures. Option C is wrong because immutable storage for a Recovery Services vault is not a supported feature; immutable storage applies to Azure Blob Storage, not backup vaults. Option D is wrong because locally redundant storage (LRS) replicates data only within a single datacenter, which does not protect against a full region failure.

40
Multi-Selecthard

Which THREE components are required to implement a disaster recovery solution for Azure SQL Database using failover groups? (Choose three.)

Select 3 answers
A.A failover group that includes both servers
B.A secondary Azure SQL Database server in another region
C.Zone-redundant configuration on the primary database
D.A primary Azure SQL Database server in one region
E.Active geo-replication configured on the primary database
AnswersA, B, D

A failover group is the coordination element: it binds a primary and secondary logical server into a single unit and owns the geo-replication relationships between their databases. It also exposes a writable listener endpoint and, optionally, a read-only endpoint, which means client applications can fail over without changing connection strings. Without this object, you would have no unified policy or endpoint to orchestrate regional failover.

Why this answer

A failover group is the core orchestration component that manages the replication and automatic or manual failover of multiple databases between a primary and secondary Azure SQL Database server. It requires both a primary server in one region and a secondary server in another region to be included in the group, enabling a coordinated disaster recovery plan with a defined failover policy.

Exam trap

The trap here is that candidates often confuse active geo-replication with failover groups, thinking both are required, when in fact failover groups subsume the replication functionality and provide a simpler management model with automatic failover capabilities.

41
MCQmedium

A company runs a multi-tier application on Azure VMs. The application has front-end and back-end VMs that must be started in a specific order during failover (front-end first, then back-end). The company uses Azure Site Recovery to replicate to a secondary region. After failover, they also need to run custom PowerShell scripts to update DNS records. Which Azure Site Recovery feature should they configure?

A.Recovery plan with manual steps
B.Recovery plan with automation runbooks and order groups
C.Failover with network mapping
D.Test failover with isolation
AnswerB

Recovery plans support order groups, so the web tier, application tier, and database tier can be assigned to separate groups that start strictly in the specified sequence. Automation runbooks can be attached as pre-action or post-action steps for each group, which lets you run custom scripts to reconfigure connections, update DNS, or mount storage right after each dependency is available. This combined capability not only satisfies the stated startup-order and script requirements but also makes failover predictable and fully automated.

Why this answer

Azure Site Recovery recovery plans support order groups to enforce the startup sequence of VMs (front-end first, then back-end) and can include automation runbooks to execute custom PowerShell scripts, such as updating DNS records after failover. This provides a structured, automated failover workflow that meets both the sequencing and scripting requirements.

Exam trap

The trap here is that candidates may confuse recovery plans with simple failover options, overlooking that recovery plans uniquely combine order groups and runbook automation to address both sequencing and custom scripting requirements in a single feature.

How to eliminate wrong answers

Option A is wrong because manual steps in a recovery plan require human intervention during failover, which contradicts the need to automatically run PowerShell scripts for DNS updates and does not inherently enforce VM startup order without additional configuration. Option C is wrong because network mapping defines how VMs connect to the target network after failover but does not control VM startup sequencing or execute custom scripts. Option D is wrong because test failover with isolation is used to validate failover in an isolated network without impacting production, but it does not provide mechanisms for startup order or script execution.

42
MCQmedium

Your organization runs a critical application on Azure VMs that must be highly available within a region. The application is stateful and requires shared storage. You need to design a solution that can automatically recover from a VM failure with minimal downtime. What should you include in the design?

A.Deploy a single VM with premium storage and Azure Backup for recovery.
B.Deploy the VMs in different Availability Zones and use Azure NetApp Files for storage.
C.Use Azure Site Recovery to replicate the VM to a secondary region.
D.Deploy the VMs in an availability set and use Azure Shared Disks for the stateful data.
AnswerD

Availability set protects from rack-level failures, and shared disks enable automatic failover.

Why this answer

An availability set distributes VMs across fault domains and update domains within a datacenter, providing redundancy for VM failures. Azure Shared Disks enable multiple VMs to attach and access the same managed disk, fulfilling the shared storage requirement for stateful applications. Option A is incorrect because a single VM with Azure Backup does not provide automatic failover; backup is for data recovery, not high availability.

Option B is incorrect because Azure NetApp Files is a shared storage service, but deploying VMs in different Availability Zones introduces cross-zone latency and is not necessary for intra-region HA; an availability set is more suitable for stateful apps requiring shared disks. Option C is incorrect because Azure Site Recovery replicates to a secondary region for disaster recovery, not for automatic recovery within a region.

43
Multi-Selectmedium

Which TWO actions should you take to ensure business continuity for an Azure App Service web app that uses Azure SQL Database? (Choose two.)

Select 2 answers
A.Configure Azure SQL Database failover groups with automatic failover.
B.Enable auto-healing in the App Service and modify the application code to handle retries.
C.Deploy the App Service app in two regions using separate App Service plans and use Azure Traffic Manager for global traffic distribution.
D.Use Azure Front Door with a single App Service instance.
E.Configure Azure Backup for the App Service and enable geo-restore.
AnswersA, C

Failover groups with automatic failover replicate Azure SQL Database to a paired secondary region and provide a listener endpoint, so the database recovers without manual intervention. This addresses the data-tier continuity requirement of the business continuity scenario.

Why this answer

Option A is correct because Azure SQL Database failover groups provide automatic geo-failover of the database to a secondary region, ensuring the data tier remains available during a regional outage without manual intervention. Option C is correct because deploying the App Service app in two regions, each with its own App Service plan, and using Azure Traffic Manager for global traffic distribution provides a multi-region, highly available web tier that can route users to a healthy region if one fails. Option B is not correct because auto-healing and retry logic only address transient application-level faults, not regional or infrastructure-level failures required for business continuity.

Option D is not correct because Azure Front Door with a single App Service instance still leaves a single point of failure in one region. Option E is not correct because Azure Backup and geo-restore are for data recovery/restore scenarios, not continuous availability or automatic failover.

Exam trap

The trap is selecting options that provide high availability within a single region (like auto-healing) or backup/restore (geo-restore) instead of true cross-region redundancy with automatic failover, which is required for business continuity.

44
MCQhard

A company runs an SAP HANA database on Azure large instances (HLI) in the West US region. The database is critical for business operations. They need a disaster recovery solution with a recovery point objective (RPO) of near zero (seconds) and a recovery time objective (RTO) of less than 30 minutes in the event of a region-wide outage. The solution must automatically replicate data to a secondary region (East US) and support automated failover. Which design should they implement?

A.Configure HANA System Replication (async) between the primary and secondary site, and use a Pacemaker cluster with Azure Load Balancer to enable automated failover
B.Use Azure Site Recovery to replicate the HANA large instance VMs with a replication frequency of 30 seconds and enable auto-failover
C.Schedule HANA database backups every 5 minutes to Azure Blob Storage with geo-redundant storage (GRS), and restore in the secondary region on demand
D.Set up HANA System Replication with synchronous mode to the secondary region
AnswerA

HANA System Replication with asynchronous mode provides near-zero RPO. Combined with Pacemaker and Azure Load Balancer, you can achieve automatic failover within the required RTO. This is the recommended approach for SAP HANA DR on Azure.

Why this answer

HANA System Replication (async) provides near-zero RPO by continuously replicating log changes to the secondary region, while a Pacemaker cluster with Azure Load Balancer enables automated failover within the required 30-minute RTO. This combination meets the strict RPO/RTO requirements for SAP HANA on Azure Large Instances, as Azure Site Recovery does not support HLI and synchronous replication would introduce unacceptable latency over the West US to East US distance.

Exam trap

The trap here is that candidates confuse Azure Site Recovery as a viable option for HLI, not realizing it only supports standard Azure VMs, or they assume synchronous replication is always better without considering the latency penalty over inter-region distances.

How to eliminate wrong answers

Option B is wrong because Azure Site Recovery does not support Azure Large Instances (HLI) — it only works with standard Azure VMs, and its 30-second replication frequency cannot achieve near-zero RPO (seconds). Option C is wrong because scheduling backups every 5 minutes cannot achieve near-zero RPO (seconds), and manual restore in the secondary region would far exceed the 30-minute RTO. Option D is wrong because synchronous HANA System Replication over the long distance between West US and East US would introduce high network latency, causing unacceptable performance impact on the primary database and potentially violating the RTO due to transaction stalls.

45
MCQmedium

A company runs SQL Server on an Azure virtual machine. They need to ensure high availability within a single Azure region. The solution must provide automatic failover with zero data loss (synchronous replication) and support read-only routing for reporting workloads. Which solution should they implement?

A.SQL Server Always On Availability Group
B.SQL Server Failover Cluster Instance (FCI)
C.Azure Site Recovery
D.Azure Backup
AnswerA

SQL Server Always On Availability Group provides database-level high availability and disaster recovery by maintaining synchronous-commit replicas. With synchronous mode, transaction commits are acknowledged only after being hardened on both primary and secondary, so automatic failover results in zero data loss. Additionally, configuring read-only routing on the secondary replica lets reporting workloads connect to a readable secondary, offloading read traffic without compromising the primary.

Why this answer

SQL Server Always On Availability Groups (AG) provide high availability and disaster recovery at the database level. They support synchronous replication with automatic failover, ensuring zero data loss (RPO=0) within a single Azure region. Additionally, AGs allow secondary replicas to be configured as readable, enabling read-only routing for reporting workloads, which directly meets all stated requirements.

Exam trap

The trap here is confusing Failover Cluster Instances (FCI) with Availability Groups; FCI provides instance-level HA with shared storage but cannot serve read-only workloads from secondary nodes, while AGs offer database-level HA with readable secondaries and synchronous replication.

How to eliminate wrong answers

Option B (SQL Server Failover Cluster Instance) is wrong because it operates at the instance level using shared storage (e.g., Azure shared disks or Storage Spaces Direct), which does not support read-only routing for reporting workloads; secondary nodes are passive and cannot serve read traffic. Option C (Azure Site Recovery) is wrong because it provides disaster recovery replication at the VM level, not database-level synchronous replication, and does not guarantee zero data loss or support read-only routing for SQL Server reporting. Option D (Azure Backup) is wrong because it is a backup and restore solution, not a high availability or automatic failover mechanism; it cannot provide synchronous replication, zero data loss failover, or read-only routing.

46
MCQhard

Your company, Fabrikam Inc., operates a global Software-as-a-Service (SaaS) application that provides real-time analytics. The application runs on Azure Kubernetes Service (AKS) with a microservices architecture. The data tier uses Azure Cosmos DB (Core SQL API) with multi-region writes. The application also uses Azure Event Hubs for event ingestion. The business requires a Recovery Time Objective (RTO) of 10 seconds and a Recovery Point Objective (RPO) of 0 for the entire platform. The solution must support active-active configuration across multiple Azure regions. You have been asked to recommend the disaster recovery design. Which option should you recommend?

A.Deploy AKS in three regions with Azure Traffic Manager. Use Azure Cosmos DB with multi-region writes. Use Azure Event Hubs with geo-disaster recovery. Use Azure Cache for Redis Enterprise with active geo-replication.
B.Deploy AKS in two regions with Azure Front Door. Use Azure Cosmos DB with single write region and auto-failover. Use Azure Service Bus with geo-disaster recovery. Use Azure Cache for Redis Enterprise with active geo-replication.
C.Deploy AKS in three regions with Azure Front Door. Use Azure Cosmos DB with multi-region writes. Use Azure Event Hubs with geo-disaster recovery and active-active pattern. Use Azure Cache for Redis Enterprise with active geo-replication.
D.Deploy AKS in two regions with Azure Front Door. Use Azure SQL Database with auto-failover groups. Use Azure Event Hubs with geo-disaster recovery. Use Azure Cache for Redis Enterprise with active geo-replication.
AnswerC

This solution meets all stated requirements through active-active replication at every layer. Azure Front Door uses anycast-based global load balancing and continuous health probes, enabling failover in less than the 10-second RTO. Azure Cosmos DB with multi-region writes accepts writes in any region, providing RPO=0 and continuous availability. Azure Event Hubs with geo-disaster recovery and an active-active pattern uses paired namespaces with client-side failover/producer logic to keep event flow uninterrupted. Azure Cache for Redis Enterprise with active geo-replication lets all regions read and write the same cache data with automatic conflict resolution, completing the zero-downtime architecture.

Why this answer

It meets the strict RTO of 10 seconds and RPO of 0 by using Azure Front Door for global load balancing with health probes, Azure Cosmos DB multi-region writes for zero data loss, Azure Event Hubs with geo-disaster recovery and active-active pattern for continuous event ingestion, and Azure Cache for Redis Enterprise with active geo-replication for synchronized caching across regions. This combination ensures that all components support active-active configuration and can fail over instantly without data loss.

Exam trap

The trap here is that candidates often assume Azure Traffic Manager or Azure SQL Database can meet sub-10-second RTO and zero RPO, but they overlook the DNS propagation delays in Traffic Manager and the inherent replication lag in SQL Database auto-failover groups.

How to eliminate wrong answers

Option A is wrong because Azure Traffic Manager does not support active-active configuration with sub-10-second failover; it relies on DNS-based routing with TTL delays, making it unsuitable for the required RTO. Option B is wrong because Azure Cosmos DB with single write region and auto-failover has a non-zero RPO (typically up to 5 seconds) and does not support active-active writes, violating the RPO of 0 requirement. Option D is wrong because Azure SQL Database with auto-failover groups has a typical RTO of 30-60 seconds and RPO of up to 5 seconds, failing both the RTO of 10 seconds and RPO of 0; additionally, it does not support active-active writes across regions.

47
MCQmedium

A company runs a critical application on Azure Virtual Machines in the North Europe region. The application uses a SQL Server database on a VM. The company wants to implement a backup solution that provides point-in-time restore for the database to any point within the last 35 days. The solution must minimize administrative effort and cost. What should you recommend?

A.Create a scheduled script that copies the database backup files to Azure Blob Storage.
B.Configure SQL Server transaction log shipping to a secondary VM.
C.Use Azure Backup to back up the SQL Server database.
D.Use Azure Site Recovery to replicate the SQL Server VM to another region.
AnswerC

Azure Backup for SQL Server on Azure VMs provides application-consistent backups and supports point-in-time restore up to 35 days. It is a fully managed solution that minimizes administrative effort and integrates with the Azure portal. It also offers long-term retention options if needed, and the cost is based on the protected instance and storage consumed.

Why this answer

Azure Backup for SQL Server on Azure VMs is a managed solution that provides application-consistent backups and supports point-in-time restore for up to 35 days. It minimizes administrative effort and cost because it is fully integrated with Azure and requires no additional infrastructure.

Exam trap

The trap here is assuming that Azure Site Recovery can provide database-level point-in-time restore.

48
MCQeasy

You are designing a disaster recovery plan for a web application hosted on Azure App Service. The application uses Azure SQL Database. The company wants to minimize downtime during a regional outage. Which approach should you recommend?

A.Deploy App Service in a single region with Azure Backup for the app and database.
B.Deploy App Service in two regions with Azure Front Door for global load balancing and Azure SQL Database active geo-replication.
C.Deploy App Service across availability zones in one region and use Azure SQL Database zone-redundant configuration.
D.Deploy App Service in two regions with Azure Traffic Manager and use manual database restore.
AnswerB

Deploying App Service in two regions behind Azure Front Door gives you global, anycast-based load balancing with health probes that automatically steer traffic away from a failed region. Meanwhile, Azure SQL Database active geo-replication maintains a continuously copied readable secondary in the paired or selected secondary region, and using a failover group enables automatic, application-transparent failover with a short RTO and low RPO. This combination delivers genuine cross-region disaster recovery: both the compute and data tiers have automated failover paths.

Why this answer

It combines multi-region App Service deployment with Azure Front Door for global load balancing and Azure SQL Database active geo-replication. This ensures that during a regional outage, traffic is automatically routed to the healthy secondary region, and the database is continuously replicated with a readable secondary, enabling near-zero RPO and minimal RTO without manual intervention.

Exam trap

The trap here is that candidates often confuse availability zones (which protect against datacenter failures within a region) with multi-region disaster recovery, leading them to choose Option C, which does not address a full regional outage.

How to eliminate wrong answers

Option A is wrong because deploying in a single region with Azure Backup does not provide automatic failover or load balancing; recovery requires manual restore and DNS changes, leading to significant downtime during a regional outage. Option C is wrong because availability zones protect only against zonal failures within a single region, not a full regional outage, and zone-redundant SQL Database does not provide cross-region failover. Option D is wrong because Azure Traffic Manager can route traffic but lacks health-based routing and SSL offload capabilities of Front Door, and manual database restore from backups results in high RTO and potential data loss, failing to minimize downtime.

49
Multi-Selecthard

A company runs a critical application on Azure VMs. They need a backup strategy that meets the following requirements: - Daily backups retained for 35 days - Weekly backups retained for 12 weeks - Monthly backups retained for 36 months - Yearly backups retained for 10 years - Backups must be stored in a geo-redundant storage account Which THREE items must be configured? (Choose three.)

Select 3 answers
A.A simple daily backup policy
B.A backup policy with GFS retention
C.Geo-redundant storage (GRS) for the vault
D.A Recovery Services vault in the paired region
E.A Recovery Services vault in the same region as the VMs
AnswersB, C, E

A backup policy with GFS (grandfather-father-son) retention directly satisfies the staggered schedule: daily, weekly, monthly and yearly tiers with independent retention durations. Recovery Services vault policies natively support these four backup frequencies, so configuring GFS retention fulfils the 35-day, 12-week, 36-month and 10-year requirements in one policy.

Why this answer

Option B is correct because the required retention scheme (daily 35 days, weekly 12 weeks, monthly 36 months, yearly 10 years) is exactly the Grandfather-Father-Son (GFS) retention pattern, which Azure Backup implements through a backup policy configured with daily, weekly, monthly, and yearly retention rules. Option C is correct because the requirement to store backups in geo-redundant storage is satisfied by setting the Recovery Services vault's storage replication type to Geo-Redundant Storage (GRS), which replicates backup data to the Azure paired region. Option E is correct because a Recovery Services vault must be created in the same region as the VMs it protects; the vault is a regional resource and cannot directly back up VMs located in a different region.

Option A is incorrect because a simple daily backup policy only provides daily retention and cannot express weekly, monthly, and yearly GFS retention tiers. Option D is incorrect because the vault itself is created in the VMs' region, not the paired region; geo-redundancy is achieved via the GRS storage setting, which asynchronously replicates data to the paired region.

Exam trap

The trap here is that candidates often confuse the need for a Recovery Services vault in the paired region (Option D) with geo-redundant storage, but Azure Backup achieves geo-redundancy by configuring GRS on the vault's storage, not by deploying a second vault.

50
MCQmedium

A company runs SQL Server on an Azure virtual machine. They need to automate database backups with application-consistency and retain backups for 10 years to meet compliance. They also want to restore to any point in time within the last 35 days. Which Azure Backup solution should they use?

A.Azure Backup for SQL Server in Azure VM
B.Azure Backup for Azure VM
C.Azure Site Recovery
D.SQL Server Always On Availability Groups
AnswerA

Azure Backup for SQL Server in Azure VM is the correct choice because it natively integrates with SQL Server's I/O and VSS to produce application-consistent backups that preserve transactional integrity. It supports full, differential, and transaction-log backups, enabling point-in-time database restoration, and offers centralized policy management with configurable long-term retention (up to 10 years) and geo-redundant storage options.

Why this answer

Azure Backup for SQL Server in Azure VM (Option A) is correct because it provides native application-consistent backups for SQL Server databases running on Azure VMs, supports long-term retention (LTR) up to 10 years using the backup vault's retention rules, and enables point-in-time restore (PITR) for the last 35 days by leveraging SQL Server transaction log backups. This solution is specifically designed for SQL Server workloads and meets both compliance and recovery requirements without additional infrastructure.

Exam trap

The trap here is that candidates often confuse Azure Backup for Azure VM (which provides crash-consistent backups) with Azure Backup for SQL Server in Azure VM (which provides application-consistent backups with PITR), leading them to choose Option B for simplicity, but only Option A meets the specific SQL Server backup and compliance requirements.

How to eliminate wrong answers

Option B is wrong because Azure Backup for Azure VM captures only VM-level snapshots (crash-consistent or file-system-consistent), not application-consistent SQL Server backups, and cannot perform SQL-specific point-in-time restores or retain transaction logs for PITR within 35 days. Option C is wrong because Azure Site Recovery is a disaster recovery (DR) solution focused on replication and failover for business continuity, not a backup service; it does not support long-term retention for 10 years or granular point-in-time restore for SQL databases. Option D is wrong because SQL Server Always On Availability Groups is a high-availability and disaster recovery feature that provides synchronous or asynchronous replication, not a backup solution; it does not automate backups, retain backups for 10 years, or offer point-in-time restore capabilities.

51
MCQmedium

A company runs a critical application on Azure VMs in a single region. They need to ensure the application can failover to another region with minimal data loss and a recovery time objective (RTO) of 1 hour. The application uses managed disks and SQL Server Always On availability groups. What is the MOST cost-effective solution that meets the requirements?

A.Use Azure geo-redundant storage (GRS) for the managed disks and restore the VMs in the secondary region
B.Use Azure Site Recovery to replicate VMs to a secondary region with a recovery plan
C.Use Azure availability zones to protect against regional failures
D.Deploy SQL Server Always On availability groups across two regions
AnswerB

Azure Site Recovery (ASR) provides continuous replication of Azure VMs to a secondary region with a defined recovery point objective (RPO) of seconds and a recovery time objective (RTO) of minutes, well within the 1-hour requirement. By creating a recovery plan, you can orchestrate the failover sequence, including start order, scripted actions, and manual actions, ensuring consistent and predictable recovery. ASR is a cost-effective managed service that does not require additional SQL Server licenses or compute resources beyond the replicated disk storage and the replication appliance (which can be scaled or shared). This makes it the recommended solution for meeting the stated RTO and RPO for critical VMs without over-engineering the architecture.

Why this answer

Azure Site Recovery (ASR) provides orchestrated replication and failover for Azure VMs, supporting both managed disks and SQL Server Always On availability groups. It meets the RTO of 1 hour by enabling a recovery plan that automates the failover sequence, and it minimizes data loss through continuous replication with a Recovery Point Objective (RPO) as low as 30 seconds. This is the most cost-effective solution because ASR replicates only changed blocks and does not require a continuously running secondary VM, unlike a full geo-redundant storage or cross-region Always On deployment.

Exam trap

The trap here is that candidates often confuse geo-redundant storage (GRS) with VM-level disaster recovery, assuming storage replication alone is sufficient for application failover, but GRS does not handle VM state, network configuration, or orchestrated recovery, making it unsuitable for meeting RTO and RPO requirements.

How to eliminate wrong answers

Option A is wrong because Azure geo-redundant storage (GRS) replicates the underlying storage asynchronously, but it does not provide VM-level replication or orchestrated failover; restoring VMs from GRS snapshots would likely exceed the 1-hour RTO and could result in significant data loss due to the asynchronous replication lag. Option C is wrong because availability zones protect only within a single region and cannot provide failover to a secondary region, which is explicitly required. Option D is wrong because deploying SQL Server Always On availability groups across two regions requires a secondary replica in the other region, which incurs ongoing compute and storage costs for the standby VM, making it less cost-effective than ASR, which only spins up resources during failover.

52
MCQmedium

A company runs a critical line-of-business application on 10 Azure VMs. They need a disaster recovery solution that replicates the VMs to a secondary region with a recovery point objective (RPO) of 30 minutes and a recovery time objective (RTO) of 1 hour. The solution must support non-disruptive testing of failover for quarterly compliance drills. Which Azure service should they use?

A.Azure Backup
B.Azure Site Recovery
C.Azure Migrate
D.Manual VM replication to secondary region
AnswerB

Azure Site Recovery provides continuous asynchronous replication of Azure VMs to a secondary region, meeting the 30-minute RPO, and supports test failover into an isolated network for non-disruptive quarterly drills while delivering the 1-hour RTO.

Why this answer

Azure Site Recovery (ASR) orchestrates replication, failover, and failback of Azure VMs to a secondary region, meeting the RPO of 30 minutes (continuous replication with 30-second RPO) and RTO of 1 hour (orchestrated recovery). It supports non-disruptive test failovers via isolated networks, which is essential for quarterly compliance drills without impacting production.

Exam trap

The trap here is that candidates confuse Azure Backup (which is for backup/restore with longer RPO) with Azure Site Recovery (which is for replication and orchestrated failover), overlooking that the question explicitly requires non-disruptive test failovers and strict RPO/RTO, which only ASR can provide.

How to eliminate wrong answers

Option A is wrong because Azure Backup provides crash-consistent or application-consistent snapshots with a minimum RPO of 1 hour (via backup policy) and does not support orchestrated failover or non-disruptive test failovers; it is designed for long-term retention and restore, not disaster recovery with strict RTO/RPO. Option C is wrong because Azure Migrate is a tool for discovery, assessment, and migration of workloads to Azure, not for ongoing replication or disaster recovery; it lacks the continuous replication and failover orchestration required. Option D is wrong because manual VM replication to a secondary region (e.g., copying VHDs or using custom scripts) cannot guarantee a 30-minute RPO or 1-hour RTO due to manual intervention, lacks automated orchestration, and does not support non-disruptive test failovers without complex custom networking.

53
MCQmedium

Your organization has a critical application deployed on Azure VMs in the West US region. The application uses a Standard_D8s_v3 VM with two data disks (512 GB each) and a separate log disk (256 GB). The application writes data continuously to the data disks and logs. The business continuity requirements are: RPO of 15 minutes, RTO of 2 hours, and the ability to recover to a specific point in time within the last 7 days. You need to design a disaster recovery solution that replicates the VMs and disks to the East US region. The solution must also support failback to West US after a disaster. What should you do?

A.Use Azure Site Recovery to replicate the VMs to East US with a recovery plan that includes the VM and disks, and configure failback using reprotection
B.Use Azure Migrate to migrate the VMs to East US and then set up replication back to West US
C.Configure Azure Backup for the VMs with a backup policy that has a 15-minute frequency and replicate backups to the East US region using geo-redundant storage
D.Use Azure Storage geo-redundant storage (GRS) for the managed disks and manually attach the disks to a new VM in East US during a disaster
AnswerA

Azure Site Recovery (ASR) is the correct choice because it provides continuous, application-consistent replication of Azure VMs to a secondary region (East US) with a recovery point objective (RPO) as low as a few seconds and a recovery time objective (RTO) that can be met via orchestrated recovery plans. Including the VM and disks in a recovery plan ensures that all dependent resources fail over in the correct order, and reprotection enables automated failback to the primary region after the disaster is resolved, fulfilling the stated DR requirement.

Why this answer

Azure Site Recovery (ASR) is the correct service for orchestrating replication, failover, and failback of Azure VMs between regions. It supports the required RPO of 15 minutes (using near-synchronous replication with change tracking) and RTO of 2 hours, and allows point-in-time recovery via recovery points. The reprotection and failback workflow enables you to replicate back to West US after a disaster, meeting the full business continuity requirements.

Exam trap

The trap here is confusing Azure Backup (which is for backup and long-term retention) with Azure Site Recovery (which is for replication and DR), leading candidates to choose a backup-based solution that cannot meet the required RPO or support failback.

How to eliminate wrong answers

Option B is wrong because Azure Migrate is designed for one-time migration, not ongoing replication with failback; it does not provide the continuous replication or orchestrated failback needed for DR. Option C is wrong because Azure Backup with a 15-minute frequency cannot achieve an RPO of 15 minutes (minimum backup frequency is 4 hours for Azure VM backup), and geo-redundant storage does not provide point-in-time recovery or automated failover orchestration. Option D is wrong because Azure Storage GRS for managed disks does not replicate disk state changes continuously or support point-in-time recovery; manually attaching disks in another region cannot meet the RTO of 2 hours and lacks orchestrated failback.

54
MCQeasy

A company runs an Azure SQL Database with active geo-replication configured to a secondary region. The primary region experiences a complete outage. The company needs to promote the secondary database to become the new primary with minimal data loss. Which action should they take?

A.Forced failover
B.Planned failover
C.Enable geo-replication
D.Failover
AnswerA

Forced failover is the appropriate action when the primary Azure SQL Database experiences a complete outage and is unreachable. This mechanism immediately promotes the secondary database to become the new primary, ensuring rapid recovery. While active geo-replication is asynchronous and some data loss is inherent if the primary cannot send its final transactions, a forced failover uses the most up-to-date data available on the secondary. This directly satisfies the requirement for minimal data loss by prioritising immediate availability with the latest replicated data.

Why this answer

Forced failover is the correct action because it immediately promotes the secondary database to primary without waiting for synchronization, which is necessary during a complete primary region outage. This option minimizes data loss by accepting any unsynchronized data at the secondary, prioritizing availability over consistency. In contrast, planned failover requires synchronous data transfer and fails if the primary is unreachable.

Exam trap

The trap here is that candidates confuse 'Failover' (which in Azure SQL Database can mean either planned or forced depending on context) with the specific 'Forced failover' action required during a disaster, leading them to select the ambiguous 'Failover' option instead.

How to eliminate wrong answers

Option B (Planned failover) is wrong because it requires the primary database to be online and fully synchronized before promoting the secondary, which is impossible during a complete outage. Option C (Enable geo-replication) is wrong because geo-replication is already configured per the scenario; re-enabling it would not promote the secondary. Option D (Failover) is wrong because 'Failover' in Azure SQL Database context typically refers to a planned failover (with no data loss) or an unplanned failover (forced), but the generic term is ambiguous; the specific action needed here is 'Forced failover' to handle the outage with minimal data loss.

55
MCQmedium

A company runs a production Azure SQL Database. They need a business continuity solution that allows point-in-time restore to any time within the last 7 days and provides geo-failover capability with RTO of 1 hour. What is the MOST COST-EFFECTIVE option?

A.Use Azure SQL Database long-term retention (LTR) for backups
B.Deploy a zone-redundant Azure SQL Database
C.Configure active geo-replication with a readable secondary in another region
D.Deploy auto-failover groups with a secondary in another region
AnswerC

Active geo-replication creates an asynchronously replicated, readable secondary database in another Azure region, enabling fast manual failover with a 1-hour RTO when you update the connection string. It supports point-in-time restore on the secondary and costs less than auto-failover groups because it doesn't require multiple databases or managed instance infrastructure. This directly satisfies the geo-disaster-recovery requirement for a single production database.

Why this answer

Active geo-replication with a readable secondary in another region meets the 7-day point-in-time restore requirement (each database has automated backups retained for 7 days by default) and provides geo-failover with an RTO of 1 hour, as the secondary is continuously synchronized and can be manually failed over. It is more cost-effective than auto-failover groups because it does not require the additional listener and routing overhead, and you pay only for the secondary compute and storage.

Exam trap

The trap here is that candidates confuse auto-failover groups (which add automated failover and a listener) with active geo-replication, assuming the extra features are required for the RTO, but the question asks for the most cost-effective option, and active geo-replication meets all stated requirements without the additional cost of the listener and forced same-tier secondary.

How to eliminate wrong answers

Option A is wrong because long-term retention (LTR) extends backup retention beyond 35 days (up to 10 years) but does not provide geo-failover capability or an RTO of 1 hour; it is purely for archival backups. Option B is wrong because zone-redundant databases protect against zonal failures within a single region, not geo-failover to another region, and do not meet the cross-region RTO requirement. Option D is wrong because auto-failover groups provide automated geo-failover with a built-in listener, but they are more expensive than active geo-replication due to the additional read/write listener endpoint and the requirement for a secondary at the same service tier and compute size, whereas active geo-replication allows a lower-cost secondary.

56
MCQmedium

Your company runs a mission-critical application on Azure VMs. You need to design a cross-region disaster recovery solution that meets a recovery time objective (RTO) of 15 minutes and a recovery point objective (RPO) of 5 minutes. The solution must minimize costs. What should you recommend?

A.Use Azure SQL Database active geo-replication with a failover group.
B.Use Azure Storage with read-access geo-redundant storage (RA-GRS) and Azure Traffic Manager.
C.Use Azure Backup with geo-redundant storage.
D.Use Azure Site Recovery with replication frequency set to 30 seconds.
AnswerD

Azure Site Recovery (ASR) continuously replicates the VM's disks to a secondary region using a replication frequency configurable down to 30 seconds, which comfortably meets the 5-minute RPO requirement. ASR provides coordinated failover with recovery plans, allowing the VM to be started in the secondary region within the 15-minute RTO target. It is the appropriate DR solution for IaaS VMs, unlike backup, geo-replication, or storage-based options, because it replicates both compute and data asynchronously with low enough lag to satisfy the stated SLA.

Why this answer

Azure Site Recovery (ASR) can replicate Azure VMs to a secondary region with a replication frequency as low as 30 seconds, enabling an RPO of 5 minutes and an RTO of 15 minutes when combined with a planned failover. This meets the mission-critical requirements while minimizing costs compared to always-on active-active solutions, as ASR only incurs costs for replication traffic and storage in the secondary region.

Exam trap

The trap here is that candidates often confuse backup (Azure Backup) with disaster recovery (Azure Site Recovery), assuming geo-redundant backup storage can meet low RPO/RTO targets, when in fact backup is designed for long-term retention and point-in-time restore, not rapid failover.

How to eliminate wrong answers

Option A is wrong because Azure SQL Database active geo-replication with a failover group is designed for PaaS databases, not for replicating entire Azure VMs running a mission-critical application; it does not replicate the VM's OS, configuration, or non-database components. Option B is wrong because read-access geo-redundant storage (RA-GRS) provides read-only access to a secondary region with an RPO typically measured in hours (due to asynchronous replication), and Azure Traffic Manager handles DNS-level routing but cannot achieve the sub-5-minute RPO or 15-minute RTO for VM failover. Option C is wrong because Azure Backup with geo-redundant storage is a backup solution, not a replication or failover solution; its RPO is typically 24 hours or more (based on backup schedule), and recovery involves restoring from a backup, which cannot meet a 15-minute RTO.

57
MCQeasy

A company uses Azure Backup to protect on-premises Windows servers and Azure VMs. They need to restore a file from a backup of an Azure VM that was deleted three months ago. The backup policy retains daily backups for 30 days and weekly backups for 12 months. What is the CORRECT way to restore the file?

A.Azure Backup does not support file-level restore for Azure VMs; restore the entire disk
B.Restore the entire VM from a weekly recovery point and then copy the file
C.Use the 'Restore to a new VM' option and select the file during the restore process
D.Use the file-level recovery option to mount the recovery point as a drive and copy the file
AnswerD

Azure Backup supports file-level recovery for Azure VMs: in the Recovery Services vault, select the recovery point and choose 'File Recovery', which downloads a script (PowerShell for Windows, bash for Linux) that mounts the recovery point as an iSCSI drive on your current VM. You then copy the required file from that mounted drive and, when finished, unmount it to release the connection. This is the correct, supported method because it gives you direct access to the file system without restoring the entire VM or recreating it.

Why this answer

Azure Backup supports file-level recovery for Azure VMs by mounting the recovery point as a network drive using iSCSI. This allows you to browse and copy individual files without restoring the entire VM or disk. Since the backup is older than 30 days but within 12 months, a weekly recovery point is available and can be used for file-level restore.

Exam trap

The trap here is that candidates assume file-level recovery is not available for Azure VMs (similar to on-premises agent backups) or that they must restore the entire VM, but Azure Backup explicitly provides a 'File Recovery' option for Azure VM backups that works even after the VM is deleted.

How to eliminate wrong answers

Option A is wrong because Azure Backup does support file-level restore for Azure VMs via the 'File Recovery' option, which mounts the recovery point as a drive. Option B is wrong because restoring the entire VM is unnecessary and inefficient; file-level recovery avoids the overhead of creating a full VM just to copy a single file. Option C is wrong because the 'Restore to a new VM' option does not allow selecting individual files during the restore process; it restores the entire VM, and file selection is only available through the file-level recovery workflow.

58
MCQhard

Your company runs a mission-critical application on Azure Virtual Machines that requires a Recovery Time Objective (RTO) of 5 minutes and a Recovery Point Objective (RPO) of 1 minute. The application uses a single VM with a managed disk. You need to design a disaster recovery solution that meets these requirements with minimal cost. What should you recommend?

A.Configure Azure Backup for the VM with a 1-minute backup frequency.
B.Store the managed disk in geo-redundant storage and use Azure Resource Manager templates to redeploy.
C.Use Azure Site Recovery to replicate the VM to a secondary region with a recovery plan.
D.Deploy a second VM in a secondary region and use continuous replication with Azure Migrate.
AnswerC

Azure Site Recovery replicates Azure VM disks continuously to a secondary region and can achieve an RPO as low as 5 seconds and an RTO of minutes, especially when you use recovery plans to sequence failover and runbook steps. Replica VMs are not continuously powered on, so you pay only for replicated storage and compute during test failovers rather than for a full standby VM. This natively meets the 5-minute RPO/RTO requirement and is the cost-effective DR service purpose-built for this scenario.

Why this answer

Azure Site Recovery (ASR) provides continuous replication with RPO as low as 30 seconds and RTO of minutes when using a recovery plan, meeting the 5-minute RTO and 1-minute RPO requirements. ASR replicates the VM to a secondary region and allows orchestrated failover with minimal cost compared to running a standby VM. This is the only option that satisfies both the RTO and RPO targets for a mission-critical application.

Exam trap

The trap here is that candidates confuse Azure Backup (designed for long-term retention with hourly/daily backups) with Azure Site Recovery (designed for replication and rapid failover), and mistakenly think backup frequency can be set to 1 minute, which is technically impossible with Azure Backup's architecture.

How to eliminate wrong answers

Option A is wrong because Azure Backup supports a minimum backup frequency of 4 hours for VM backups (or 12 hours for enhanced policy), far exceeding the 1-minute RPO requirement, and RTO is typically hours due to restore time. Option B is wrong because geo-redundant storage (GRS) for managed disks provides asynchronous replication with an RPO of typically 15 minutes or more, and redeploying via ARM templates does not guarantee a 5-minute RTO due to provisioning delays and lack of pre-staged resources. Option D is wrong because Azure Migrate is a discovery and migration tool, not a disaster recovery replication service; it does not provide continuous replication for DR, and deploying a second VM with manual replication would be costly and fail to meet RTO/RPO without orchestration.

59
MCQmedium

A company runs SQL Server on Azure VMs using SQL Server Standard Edition. They need a disaster recovery solution that replicates the database to a secondary Azure region with a recovery point objective (RPO) of 15 minutes and a recovery time objective (RTO) of 2 hours. They cannot use Always On Availability Groups due to licensing constraints. They also need to perform non-disruptive disaster recovery drills. Which Azure service should they implement?

A.Azure Backup for SQL Server
B.Azure Site Recovery
C.SQL Server Log Shipping to an Azure VM
D.Geo-replication for Azure SQL Database
AnswerB

Azure Site Recovery continuously replicates Azure VM disks using snapshot technology and can create application-consistent recovery points for SQL Server workloads. It provides automatic failover and, crucially, non-disruptive test failover so you can validate DR readiness without touching production. With properly configured replication frequency and timeouts, ASR can achieve recovery point objectives around 15 minutes and recovery time objectives within 2 hours, meeting the stated requirement.

Why this answer

Azure Site Recovery (ASR) replicates entire SQL Server VMs (including their databases) to a secondary Azure region, supporting RPOs as low as 30 seconds and RTOs of 2 hours or less. It allows non-disruptive disaster recovery drills by performing test failovers in an isolated network without affecting the production environment. This solution avoids the licensing constraints of Always On Availability Groups and works with SQL Server Standard Edition.

Exam trap

The trap here is that candidates often confuse Azure Site Recovery (VM-level replication) with Azure Backup (file/volume-level backup) or assume that log shipping can meet the drill requirement, but ASR is the only option that provides automated, non-disruptive test failovers for IaaS SQL Server VMs.

How to eliminate wrong answers

Option A is wrong because Azure Backup for SQL Server is designed for long-term retention and point-in-time restore, not for continuous replication to a secondary region with a 15-minute RPO or for performing non-disruptive DR drills. Option C is wrong because SQL Server Log Shipping to an Azure VM requires manual failover and does not support automated, non-disruptive DR drills; it also has higher RTO and RPO variability compared to ASR. Option D is wrong because Geo-replication for Azure SQL Database applies only to Azure SQL Database (PaaS), not to SQL Server running on Azure VMs (IaaS).

60
MCQhard

Refer to the exhibit. This ARM template configures backup for an Azure App Service web app. The backup is scheduled daily. What is the primary limitation of this backup strategy in meeting a disaster recovery RPO of 4 hours?

A.The backup storage account is in the same region as the web app
B.The backup frequency is 1 day, resulting in an RPO of up to 24 hours
C.The retention period of 30 days is too short
D.The backup does not include the web app configuration
AnswerB

A daily backup schedule means that at any given time, the most recent recoverable point can be up to 24 hours old, so the effective RPO is 24 hours. To satisfy a 4-hour RPO, backups must be taken at least every 4 hours—for example, six scheduled backups per day—or supplemented by more frequent manual backups. Since the requirement states a maximum RPO of 4 hours, the daily frequency is the specific reason this ARM template configuration fails.

Why this answer

The backup frequency is set to 1 day, meaning the most recent backup could be up to 24 hours old. To meet a Recovery Point Objective (RPO) of 4 hours, you need backups taken at least every 4 hours. Azure App Service backup does not support sub-daily scheduling natively; you would need to use Azure Backup or custom logic to achieve a 4-hour RPO.

Exam trap

The trap here is that candidates may focus on the storage account being in the same region (a common disaster recovery concern) or the retention period, but the core issue is that the daily backup frequency cannot meet a 4-hour RPO.

How to eliminate wrong answers

Option A is wrong because the backup storage account being in the same region as the web app does not affect the RPO; it affects regional disaster recovery but not the frequency of backups. Option B is correct as explained. Option C is wrong because the retention period of 30 days is unrelated to RPO; RPO concerns how much data you could lose, not how long you keep backups.

Option D is wrong because the ARM template includes the 'siteConfig' section, which backs up the web app configuration; even if it didn't, configuration is not the primary factor for RPO.

61
MCQmedium

A company runs a critical application on an Azure virtual machine in the West US region. They want to enable disaster recovery to East US with the ability to perform non-disruptive DR drills. They need an RPO of a few minutes. Which Azure service should they use?

A.Azure Site Recovery
B.Azure Backup
C.Azure Traffic Manager
D.Azure Blueprints
AnswerA

Azure Site Recovery is the correct disaster recovery solution because it continuously replicates Azure VM disks asynchronously to the paired region, enabling a low recovery point objective (RPO) that can be as low as 30 seconds for supported workloads. It also provides orchestrated failover and test failover capabilities, allowing you to validate recovery plans in an isolated test network without affecting the production environment. Recovery plans can automate the startup order of multi-tier applications, making ASR a true DR orchestration tool rather than just a data protection service.

Why this answer

Azure Site Recovery (ASR) is the correct service because it provides continuous replication of Azure VMs from a primary region (West US) to a secondary region (East US) with a Recovery Point Objective (RPO) of a few minutes. It also supports non-disruptive disaster recovery drills by allowing you to perform test failovers in an isolated network without impacting the production workload.

Exam trap

The trap here is that candidates often confuse Azure Backup (which is for long-term retention) with Azure Site Recovery (which is for replication and failover), leading them to choose Backup for DR scenarios that require low RPO and non-disruptive testing.

How to eliminate wrong answers

Option B (Azure Backup) is wrong because it is designed for long-term backup and retention, not for low-RPO replication or non-disruptive DR drills; its RPO is typically hours or days, not a few minutes. Option C (Azure Traffic Manager) is wrong because it is a DNS-based traffic load balancer for distributing incoming traffic across endpoints, not a replication or failover service for disaster recovery with a specific RPO. Option D (Azure Blueprints) is wrong because it is a governance and compliance tool for defining repeatable Azure resource templates, not a disaster recovery or replication service.

62
Multi-Selecteasy

Which TWO of the following are valid options to achieve high availability for Azure SQL Database? (Choose two.)

Select 2 answers
A.Deploy a single database with locally redundant storage (LRS)
B.Deploy a zone-redundant Azure SQL Database
C.Configure manual failover to a secondary replica in the same region
D.Configure SQL Server Always On availability groups
E.Configure active geo-replication to a secondary database in a different region
AnswersB, E

A zone-redundant Azure SQL Database automatically replicates both compute and storage across multiple availability zones within the same region. This configuration provides an availability SLA of 99.995% and enables transparent failover to another zone without any application changes. It is a valid, supported option for achieving high availability within a single Azure region.

Why this answer

Azure SQL Database offers zone-redundant configuration that automatically replicates databases across multiple Azure Availability Zones within the same region, providing an SLA of 99.995% uptime. This built-in high availability feature uses quorum-based commit and automatic failover without any manual intervention, ensuring data durability and business continuity during zone-level failures.

Exam trap

The trap here is that candidates often confuse the high availability features of Azure SQL Database (PaaS) with those of SQL Server on Azure VMs (IaaS), mistakenly selecting Always On availability groups or manual failover options that are not applicable to the managed service.

63
MCQhard

You are designing a business continuity solution for a globally distributed SaaS application that uses Azure Cosmos DB for its operational store. The application must survive a complete regional outage with zero data loss and automatic failover. What should you use?

A.Configure a single write region in Cosmos DB with eventual consistency and manual failover.
B.Configure Cosmos DB with a single write region, strong consistency, and enable automatic failover to a secondary region.
C.Enable multi-region writes in Cosmos DB with eventual consistency and automatic failover.
D.Use Azure SQL Database with active geo-replication and automatic failover.
AnswerB

Strong consistency in Azure Cosmos DB ensures that all reads return the most recently committed write, and with a single write region, writes are synchronously replicated to the secondary region before acknowledgment. This guarantees an RPO of zero because no acknowledged data is lost during a regional outage. Enabling automatic failover allows Cosmos DB to detect a region failure and redirect traffic without manual intervention, thereby satisfying the required RTO target.

Why this answer

It combines a single write region with strong consistency and automatic failover, which guarantees zero data loss during a regional outage. Strong consistency ensures that all reads reflect the latest write, and automatic failover allows Azure to promote a secondary read region to the primary write region without manual intervention, meeting the requirement for zero data loss and automatic failover.

Exam trap

The trap here is that candidates often assume multi-region writes (Option C) are necessary for zero data loss, but they overlook that multi-region writes require eventual consistency and conflict resolution, which can lead to data loss or conflicts, whereas a single write region with strong consistency and automatic failover provides the strictest guarantee of zero data loss.

How to eliminate wrong answers

Option A is wrong because eventual consistency does not guarantee zero data loss—writes acknowledged in the primary region may not be replicated to the secondary before a failover, leading to potential data loss. Option C is wrong because multi-region writes with eventual consistency can cause write conflicts and does not guarantee zero data loss; conflict resolution may drop or merge writes, violating the zero data loss requirement. Option D is wrong because Azure SQL Database with active geo-replication is not the correct service for a globally distributed SaaS application that uses Azure Cosmos DB as its operational store; the question specifically requires a Cosmos DB solution, and SQL Database does not provide the same global distribution and multi-model capabilities.

64
MCQhard

You are reviewing a recovery plan for Azure Site Recovery. The exhibit shows a snippet of the recovery plan configuration. What is the purpose of the script action defined in the exhibit?

A.To run a custom script on the recovered VMs after they boot up during test and unplanned failover.
B.To run a script before the VMs shut down during failover.
C.To update the Azure DNS records after failover.
D.To run a script only during planned failover from the primary to the recovery region.
AnswerA

This correctly describes the purpose. In Azure Site Recovery recovery plans, script actions are grouped into Boot and Shutdown groups, with the Boot group running after the virtual machines have started. The recovery plan is triggered for both Test Failover and Unplanned Failover, as indicated by the failoverTypes settings, so the custom script executes post-boot in those scenarios. This is a common way to perform configuration, application startup, or health checking on the recovered instances.

Why this answer

The script action in an Azure Site Recovery recovery plan is configured to run after the VMs have booted up, allowing custom tasks such as installing software, modifying configurations, or verifying connectivity. This is supported during both test failover and unplanned failover, as the script executes post-boot on the recovered VMs.

Exam trap

The trap here is that candidates confuse the script action's timing (post-boot) with pre-shutdown actions or assume it only applies to planned failover, overlooking the test and unplanned failover checkboxes in the exhibit.

How to eliminate wrong answers

Option B is wrong because a script action defined in the recovery plan runs after VMs boot, not before they shut down; pre-shutdown scripts are configured separately in the plan's pre-group actions. Option C is wrong because Azure Site Recovery does not natively update Azure DNS records; DNS updates require custom scripting or Azure Automation runbooks, but the exhibit shows a script action, not a DNS-specific action. Option D is wrong because the script action in the exhibit is not limited to planned failover; it applies to test and unplanned failover as well, as indicated by the 'Failover' and 'Test Failover' checkboxes.

65
MCQmedium

A database workload has an RPO of 15 minutes and an RTO of 4 hours. Cost is more important than near-zero data loss. Which design is usually more appropriate than synchronous multi-region replication?

A.Use scheduled backups or asynchronous replication aligned to the RPO/RTO.
B.Use synchronous replication across every Azure region.
C.Run the database on a single VM with no backups.
D.Use a public DNS CNAME only.
AnswerA

Scheduled backups taken every 15 minutes, or asynchronous replication with a similar lag, can restore the database to within 15 minutes of a failure, and a 4-hour RTO gives ample time to recover from those backups. This approach balances the stated RPO and RTO with cost efficiency, since the requirement does not justify the expense and added latency of synchronous multi-region replication. Azure SQL Database automated backups or Azure Site Recovery with log shipping are examples of such aligned solutions.

Why this answer

The workload's RPO of 15 minutes and RTO of 4 hours, combined with a cost-sensitive requirement that deprioritizes near-zero data loss, makes synchronous multi-region replication overkill. Scheduled backups (e.g., every 15 minutes using Azure SQL Database automated backups with point-in-time restore) or asynchronous replication (e.g., Azure SQL Database active geo-replication with a recovery point objective of up to 5 seconds, but here we can tune it to meet 15 minutes) provide sufficient protection at a lower cost, avoiding the latency and expense of synchronous replication across regions.

Exam trap

The trap here is that candidates often assume synchronous replication is always the best choice for business continuity, but the question explicitly prioritizes cost over near-zero data loss, making asynchronous replication or scheduled backups the more appropriate and cost-effective design.

How to eliminate wrong answers

Option B is wrong because synchronous replication across every Azure region would incur high latency, significant cost, and unnecessary complexity for a workload that tolerates up to 15 minutes of data loss and 4 hours of downtime; it is designed for near-zero RPO scenarios, which the question explicitly de-emphasizes. Option C is wrong because running the database on a single VM with no backups provides no recovery point or recovery time guarantee, violating the stated RPO of 15 minutes and RTO of 4 hours entirely. Option D is wrong because a public DNS CNAME only provides DNS-level redirection, not any database replication, backup, or failover capability, so it cannot meet the RPO or RTO requirements.

66
MCQhard

Refer to the exhibit. The JSON snippet shows the properties of a replication-protected item in Azure Site Recovery. What is the MOST LIKELY reason for the replication health being 'Critical'?

A.The replication storage account is misconfigured
B.There is a network connectivity issue between the on-premises site and Azure
C.A planned failover was completed, stopping replication
D.A test failover was initiated but not cleaned up
AnswerC

Azure Site Recovery intentionally stops the continuous replication stream during a planned failover to guarantee that no data written after the cutover is replicated; once this completes, the protection state is set to 'PlannedFailoverCompleted'. The replication health automatically becomes 'Critical' because the active replication link is no longer transferring data—this is an expected result of the failover lifecycle, not a sign of misconfiguration or infrastructure failure. To restore a healthy state, you must commit or reverse the failover and then re-protect the workload, which establishes a fresh replication relationship; until then, the critical health flag correctly indicates that replication is stopped.

Why this answer

When a planned failover is completed in Azure Site Recovery, replication is automatically stopped and the replication health status changes to 'Critical' because the protected item is no longer actively replicating to the recovery region. This is expected behavior after a planned failover, as the source and target are now synchronized and replication is disabled to prevent data overwrites. The 'Critical' health indicator in this context reflects the intentional cessation of replication, not a fault.

Exam trap

The trap here is that candidates often assume 'Critical' replication health always indicates a technical failure (e.g., network or storage issues), but in Azure Site Recovery, a planned failover intentionally stops replication, causing the health to become 'Critical' as a normal post-failover state.

How to eliminate wrong answers

Option A is wrong because a misconfigured replication storage account would typically cause replication errors or failures, not a clean 'Critical' health status after a planned failover; the JSON snippet shows no storage account misconfiguration details. Option B is wrong because a network connectivity issue would manifest as replication errors, missed recovery points, or a 'Warning' status, not a definitive 'Critical' status with replication stopped; the JSON shows replication is disabled, not failing. Option D is wrong because a test failover that is not cleaned up would leave the test virtual machine running in Azure but would not stop ongoing replication; the replication health would remain healthy or show a warning, not become 'Critical' with replication disabled.

67
Multi-Selectmedium

Which THREE Azure services can be used to implement a disaster recovery plan for Azure Virtual Desktop (AVD) that meets an RTO of 2 hours and an RPO of 30 minutes? (Select THREE.)

Select 3 answers
A.Azure Database for MySQL
B.Azure Migrate
C.Azure Site Recovery
D.Azure Backup
E.Azure Files with geo-redundant storage
AnswersC, D, E

Azure Site Recovery (ASR) is the core DR orchestration service for AVD session host VMs, because it continuously replicates Azure VMs to a secondary region and enables one-click failover with defined RPO/RTO. By protecting the session host VMs in a Recovery Services vault, ASR ensures compute infrastructure is promptly recreated after a regional outage. However, it does not replicate FSLogix user profiles, which is why it must be combined with geo-redundant Azure Files.

Why this answer

Azure Site Recovery (ASR) orchestrates replication and failover of Azure Virtual Desktop (AVD) session hosts and their workloads to a secondary Azure region, enabling RTO of 2 hours and RPO of 30 minutes when configured with replication policies set to 30-minute frequency. It supports multi-VM consistency groups to ensure application-consistent recovery points for AVD infrastructure components.

Exam trap

The trap here is that candidates often confuse Azure Migrate (a migration tool) with Azure Site Recovery (a DR orchestration service), or assume that Azure Backup alone can meet the RTO/RPO for AVD without considering the need for full infrastructure replication and failover.

68
Multi-Selecthard

You are designing a business continuity solution for a global SaaS application that runs on Azure Kubernetes Service (AKS) with Azure Cosmos DB as the database. The solution must support multi-region writes and automatic failover with zero data loss. Which THREE components should you include in your design? (Choose three.)

Select 3 answers
A.Deploy Azure Cache for Redis Enterprise with active geo-replication.
B.Deploy Azure Front Door with origin groups for the AKS clusters.
C.Use Azure Traffic Manager to route traffic to the primary region.
D.Configure Azure Cosmos DB with multiple write regions.
E.Use Azure SQL Database with failover groups for the database tier.
AnswersA, B, D

Azure Cache for Redis Enterprise uses active geo-replication to create a global cache cluster spanning two or more regions, where every participating cache accepts both reads and writes and synchronizes asynchronously with built-in conflict resolution. If a regional data center fails, the remaining cache automatically continues serving traffic without a manual failover step, preserving cache availability and reducing impact to application sessions. This makes it a true active-active cache tier rather than a passive replica, which is why it is correct for a global business continuity design.

Why this answer

Azure Cache for Redis Enterprise with active geo-replication is correct because it provides a globally distributed cache that supports multi-region writes and automatic failover with zero data loss. This ensures that cached data remains consistent across regions, which is critical for a global SaaS application requiring high availability and low latency.

Exam trap

The trap here is that candidates often confuse Azure Traffic Manager with Azure Front Door, but Traffic Manager lacks application-layer health probes and automatic failover with zero data loss, making it unsuitable for this scenario.

69
MCQhard

You are designing a business continuity solution for a critical application that uses Azure Cosmos DB with multiple write regions. The application is deployed in the East US and West Europe regions. The business requires that if one region fails, the application can continue to serve writes in the remaining region with no data loss. Which consistency level should you use?

A.Strong
B.Eventual
C.Session
D.Bounded staleness
AnswerD

Bounded staleness is the strongest consistency level supported with multi-master writes. It provides a bounded lag on data staleness, which helps minimize data loss compared to Eventual or Session, though it cannot guarantee zero data loss.

Why this answer

Azure Cosmos DB does not support strong consistency when multiple write regions are enabled. The supported consistency levels for multi-region writes are Eventual, Session, and Bounded staleness. None of these guarantees zero data loss during a regional failure, because writes that have not yet been replicated to the surviving region can be lost.

Bounded staleness limits how far the data can lag behind, but it does not eliminate data loss. To meet a strict no-data-loss requirement, you must use a single write region with strong consistency (or another architecture that ensures synchronous replication before acknowledging writes). Therefore, the requirement as stated cannot be satisfied by any of the listed consistency levels in a multi-write-region configuration.

Exam trap

Candidates often assume that strong consistency is available with multiple write regions, but it is not. They may also think that Bounded staleness guarantees zero data loss, but it only provides a bounded lag, not complete data loss prevention.

How to eliminate wrong answers

Option B (Eventual) is wrong because it allows writes to be replicated asynchronously, which can result in data loss if a region fails before replication completes. Option C (Session) is wrong because it guarantees consistency only within a single client session, not across regions, and does not prevent data loss during a regional failure. Option D (Bounded staleness) is wrong because it allows a configurable lag (time or operations) before writes are fully replicated, which could lead to data loss if the lag exceeds the failure window.

70
MCQmedium

Your company runs a critical web application on Azure Virtual Machines in a single region. You need to design a disaster recovery solution that meets a Recovery Point Objective (RPO) of 15 minutes and a Recovery Time Objective (RTO) of 1 hour. The solution must be cost-effective for a planned failover test. What should you do?

A.Configure Azure Site Recovery (ASR) with replication to a paired secondary region and perform regular test failovers.
B.Create a read-only replica of the VMs in another region using Azure SQL Database geo-replication.
C.Deploy the VMs across two Azure Availability Zones within the same region.
D.Use Azure Backup with daily backups to a Recovery Services vault in a paired region.
AnswerA

Azure Site Recovery replicates the entire VM workload continuously at the storage and compute level to the paired region, achieving an RPO of just a few minutes and a practical RTO of 15–30 minutes. Application-consistent snapshots ensure crash-consistent recovery, while periodic test failovers exercise the recovery plan in an isolated network without affecting production or incurring standby costs. This is the only option that provides both replication-based DR and a low enough RPO/RTO for critical web workloads.

Why this answer

Azure Site Recovery (ASR) replicates Azure VMs to a paired secondary region with near-synchronous replication, achieving an RPO of 15 minutes and an RTO of 1 hour. It supports cost-effective test failovers by performing non-disruptive drills in an isolated network, validating recovery without impacting production.

Exam trap

The trap here is that candidates confuse Azure Backup (snapshot-based, high RPO) with Azure Site Recovery (continuous replication, low RPO), or assume Availability Zones provide regional disaster recovery when they only protect against datacenter failures.

How to eliminate wrong answers

Option B is wrong because Azure SQL Database geo-replication applies only to PaaS SQL databases, not to VMs running custom applications; it does not replicate the entire VM state. Option C is wrong because deploying across Availability Zones protects only against zonal failures within the same region, not against a full regional disaster, and thus cannot meet the RPO/RTO for cross-region recovery. Option D is wrong because Azure Backup with daily backups provides an RPO of 24 hours (or at best 12 hours with enhanced policy), which exceeds the required 15-minute RPO, and restores take longer than 1 hour, failing the RTO.

71
Drag & Dropmedium

Drag and drop the steps to configure an Azure Application Gateway with end-to-end TLS encryption into the correct order.

Drag or tap steps into the slots.

Steps
Order
1Step 1
2Step 2
3Step 3
4Step 4

Why this order

First, have the certificate. Upload it, configure the backend, set up HTTP settings with TLS, then create the rule.

72
MCQeasy

A company runs a critical application on Azure VMs. They need to ensure that if an entire Azure region fails, the application can be recovered in another region with minimal data loss. They have a recovery point objective (RPO) of 1 hour and a recovery time objective (RTO) of 4 hours. What should they implement?

A.Azure Traffic Manager
B.Azure Front Door
C.Azure Site Recovery
D.Azure Backup
AnswerC

Azure Site Recovery continuously replicates Azure VM disks to a designated secondary region using crash-consistent and app-consistent snapshots, enabling a recovery point objective (RPO) as low as 15 seconds and rapid failover when the primary site fails. It also replicates networking and compute configuration, and supports planned/unplanned failover plus failback. This directly meets the critical application's need for low RPO and RTO, making it the correct answer.

Why this answer

Azure Site Recovery (ASR) orchestrates replication, failover, and failback of Azure VMs to a secondary region, meeting the RPO of 1 hour (typically 30 seconds to 15 minutes for Azure-to-Azure replication) and RTO of 4 hours (failover can be completed in minutes to a few hours, depending on VM count and data size). It is the correct service for full disaster recovery with minimal data loss across regions.

Exam trap

The trap here is confusing backup (Azure Backup) with disaster recovery (Azure Site Recovery); backup is for long-term retention with higher RPO/RTO, while Site Recovery is for rapid failover with low RPO/RTO, and candidates often pick Backup because it 'protects data' without considering the strict RPO/RTO requirements.

How to eliminate wrong answers

Option A is wrong because Azure Traffic Manager is a DNS-based traffic load balancer that routes incoming traffic to healthy endpoints but does not replicate VM data or provide automated failover of compute and storage; it cannot meet RPO/RTO for application recovery after a region failure. Option B is wrong because Azure Front Door is a global HTTP/HTTPS load balancer and application delivery controller that provides acceleration and WAF, but it does not handle VM replication or orchestrated failover; it relies on backend health probes and cannot recover VMs in a secondary region. Option D is wrong because Azure Backup provides backup and restore of VM data to a Recovery Services vault, but its RPO is typically 12-24 hours for daily backups and RTO can be hours to days for full VM restore, failing to meet the 1-hour RPO and 4-hour RTO; it is designed for data protection, not rapid disaster recovery.

73
MCQeasy

A company runs a stateless web application on multiple Azure VMs behind a load balancer. They want to ensure that if a VM fails, traffic is automatically redirected to healthy VMs. Which Azure service provides this functionality with health probes?

A.Azure Traffic Manager
B.Azure Front Door
C.Azure Application Gateway
D.Azure Load Balancer
AnswerD

Azure Load Balancer provides Layer 4 (TCP/UDP) load balancing for inbound traffic to a backend pool of VMs in the same region, distributing flows according to the configured rule. It continuously runs health probes against each VM and automatically removes any VM that fails its probe, sending subsequent traffic only to healthy instances. This satisfies the requirement for basic VM health monitoring and automatic rerouting without adding Layer 7 features like URL inspection or SSL termination.

Why this answer

Azure Load Balancer (Option D) is the correct choice because it is designed to distribute traffic across multiple VMs in the same region and uses health probes (TCP or HTTP) to monitor the health of each backend VM. If a probe fails, the load balancer automatically stops sending new traffic to that VM and redirects it to the remaining healthy instances, ensuring high availability for the stateless web application.

Exam trap

The trap here is that candidates often confuse Azure Load Balancer with Azure Traffic Manager or Azure Front Door, thinking that any 'load balancing' service can handle VM-level health probes, but only Azure Load Balancer is designed for regional, layer-4 traffic distribution with health probe-based failover for VMs behind a load balancer.

How to eliminate wrong answers

Option A is wrong because Azure Traffic Manager is a DNS-based global traffic routing service that directs traffic across regions, not to individual VMs behind a load balancer, and it does not use health probes to reroute traffic at the VM level. Option B is wrong because Azure Front Door is a global application delivery network that provides HTTP load balancing and web application firewall capabilities, but it is designed for global multi-region scenarios and not for simple regional VM-level health probe-based failover. Option C is wrong because Azure Application Gateway is a layer-7 load balancer with SSL termination and URL-based routing, but for a stateless web application behind a load balancer where only basic health probe-based failover is needed, Azure Load Balancer is the simpler and more appropriate service.

74
MCQmedium

Refer to the exhibit. You are reviewing the replication health of an on-premises Hyper-V VM replicated to Azure using Azure Site Recovery. The JSON output shows the properties of the replicated item. The replication health is 'Normal', but the last recovery point is from 2 hours ago. You need to ensure the Recovery Point Objective (RPO) of 15 minutes is met. What is the most likely cause of the issue?

A.The VM's application-consistent snapshot is failing.
B.The target region is not correctly configured in the recovery plan.
C.The Hyper-V host is not registered with the Recovery Services vault.
D.The replication frequency is set to 30 minutes or more.
AnswerD

Azure Site Recovery generates recovery points based on a configured replication frequency, which for Hyper-V can be 30 seconds, 5 minutes, 15 minutes, or a custom interval. The exhibit shows the latest recovery point is 2 hours old, while the health is 'Normal' — this combination implies the replication policy's frequency is set to 30 minutes or more, allowing the RPO to be met. If the frequency were 15 minutes, the latest recovery point would be within 15 minutes of current time under healthy conditions. Therefore, the stale recovery point is a direct consequence of a long replication frequency, not an error.

Why this answer

The replication frequency for Hyper-V replication to Azure using Azure Site Recovery (ASR) can be set to 30 seconds, 5 minutes, or 15 minutes. If the last recovery point is 2 hours old despite 'Normal' health, the replication frequency is likely configured to 30 minutes or more, which directly prevents meeting a 15-minute RPO. ASR's replication frequency setting controls how often changes are sent to Azure, and a value exceeding 15 minutes would cause the observed gap.

Exam trap

The trap here is that candidates often assume 'Normal' health means all replication settings are optimal, overlooking that the replication frequency is a separate configurable parameter that directly controls the RPO, and a 2-hour gap can occur even with healthy replication if the frequency is set too high.

How to eliminate wrong answers

Option A is wrong because a failing application-consistent snapshot would typically cause the replication health to show a warning or critical status, not 'Normal', and would affect crash-consistent recovery points as well. Option B is wrong because the target region configuration in a recovery plan affects failover behavior, not the replication frequency or the timing of recovery points. Option C is wrong because if the Hyper-V host were not registered with the Recovery Services vault, the replicated item would not appear in the JSON output at all, and replication would not be active.

75
MCQhard

A company runs a mission-critical application on Azure VMs in West US. They need a disaster recovery plan with an RPO of 5 minutes and an RTO of 30 minutes. The application consists of multiple VMs that must be recovered in a specific order: the database VM first, then the front-end VMs. They also need to ensure that after failover, the IP addresses of the VMs are retained to avoid DNS propagation delays. The company wants to test the recovery process periodically without affecting production. Which Azure Site Recovery features should they use?

A.Use recovery plans with virtual machine group ordering and failover network settings to assign static IPs.
B.Use failover settings with retention IP and test failover.
C.Use recovery plans with custom scripts for ordering and Azure Traffic Manager for IP retention.
D.Use Azure Site Recovery with Application Consistent Snapshots and ignore IP retention.
AnswerA

Recovery plans allow you to create groups of VMs and specify the order of failover. Failover network settings enable you to assign static IP addresses to the recovered VMs. Test failover is supported for drills.

Why this answer

Azure Site Recovery recovery plans allow you to define the order of VM recovery using groups, and you can assign static IP addresses via failover network settings to retain IPs after failover. This meets the RPO of 5 minutes (via continuous replication) and RTO of 30 minutes (via orchestrated failover), while test failover can be performed without impacting production.

Exam trap

The trap here is that candidates often confuse Azure Traffic Manager (a DNS-based traffic routing service) with Site Recovery's built-in IP retention capabilities, or they assume that 'retention IP' is a standalone feature rather than a configuration within failover network settings.

How to eliminate wrong answers

Option B is wrong because 'retention IP' is not a valid Azure Site Recovery feature; IP retention is achieved through failover network settings, not a separate 'retention IP' option, and test failover alone does not address VM ordering. Option C is wrong because Azure Traffic Manager is used for global load balancing and DNS-based traffic routing, not for IP retention in Site Recovery; custom scripts in recovery plans can help with ordering but are not the primary feature for static IP assignment. Option D is wrong because ignoring IP retention would cause IP address changes after failover, leading to DNS propagation delays, which contradicts the requirement to avoid such delays; Application Consistent Snapshots address data consistency but not IP retention or VM ordering.

Page 1 of 3 · 152 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Design business continuity solutions questions.